跳转到内容

ak.schema.service_operation_dtos.v1

← Schemas

Arkret Service Operation DTOs
ak.schema.service_operation_dtos.v1 · file: schemas/service-operation-dtos.schema.json

Canonical DTOs reachable from current authority-commit operations. Every definition is part of the current operation closure.

* $ · anyOf[61]
Canonical DTOs reachable from current authority-commit operations. Every definition is part of the current operation closure.
anyOf · anyOf[0] · object · $ref #/$defs/AcceptedDevicePossessionProof
Accepted-device Ed25519 possession proof shared by human SessionGrant issue and refresh. The signature covers utf8('ak.session_grant_accepted_device_possession_proof.v1\n') followed by RFC 8785 JCS of this complete object with signature omitted. It is not a server challenge: freshness comes from the <=300 second signed window, the one-time account handoff or predecessor grant, the issuer request identity, and issuer-ledger exact replay. The origin Station MUST verify this proof with the durable current accepted-device key in the same linearization that evaluates current authorization.
allOf · allOf[0] · ?
* context · const "ak.session_grant_accepted_device_possession_proof.v1"
enum: "ak.session_grant_accepted_device_possession_proof.v1"
* purpose · string (enum)
enum: "session_grant_issue" "session_grant_refresh"
request_id · string
pattern: ^ak:request:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$
account_subject · string
pattern: ^sha256:[0-9a-f]{64}$
account_handoff_grant_digest · string
SHA-256 digest of the exact opaque DPoP-bound account_handoff_grant presented in Authorization; the credential itself MUST NOT enter the proof or logs.
pattern: ^sha256:[0-9a-f]{64}$
predecessor_session_grant_id · string · $ref ./common-ids.schema.json#/$defs/session_grant_id
pattern: ^ak:session_grant:[A-Za-z0-9_-]{44}$
* account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id · $ref #/$defs/did_core_id · $ref #/$defs/did_core_id
* station_id · $ref #/$defs/did_core_id · $ref #/$defs/did_core_id
* device_id · string · $ref ./common-ids.schema.json#/$defs/device_id
pattern: ^ak:device:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$
* audience_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* holder_jkt · string
RFC 7638 thumbprint of the DPoP holder key for the handoff or predecessor SessionGrant.
pattern: ^[A-Za-z0-9_-]{43}$
* session_intent_digest · string
Digest of the complete canonical immutable issue or refresh intent.
pattern: ^sha256:[0-9a-f]{64}$
* issued_at · string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
* expires_at · string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
* verification_method · string
DID URL of the accepted device key; its fragment MUST identify device_id and its bare did MUST project to account_id.principal_id.
pattern: ^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$
* signature · string
64-byte raw Ed25519 signature encoded as canonical unpadded base64url.
pattern: ^[A-Za-z0-9_-]{86}$
anyOf · anyOf[1] · oneOf[2] · $ref #/$defs/ActorPrivateEventSubmitOutcome
Closed outcome of ak.self.actor_private_events.command.submit.v1, discriminated by event_kind. accepted_event_id is the event_id of the accepted Event, and an exact retry returns the first stored outcome. Only ak.device.push_route carries the accepted per-route revision its next write must name as expected_server_revision. No RealmCommit exists for these writes.
oneOf · oneOf[0] · object
* event_kind · const "ak.device.push_route"
enum: "ak.device.push_route"
* accepted_event_id · string · $ref #/$defs/EventId
pattern: ^ak:event:[A-Za-z0-9_-]{44}$
* revision · integer
oneOf · oneOf[1] · object
* event_kind · string (enum)
enum: "ak.agent.action_reject" "ak.agent.action_request" "ak.agent.draft.propose"
* accepted_event_id · string · $ref #/$defs/EventId
pattern: ^ak:event:[A-Za-z0-9_-]{44}$
anyOf · anyOf[2] · object · $ref #/$defs/ActorPrivateEventSubmitRequestBody
Request of ak.self.actor_private_events.command.submit.v1: exactly one caller-signed actor-private Event of a kind that has no dedicated submit operation. The service validates the exact Event bytes and MUST NOT rebuild the payload or co-sign. No approval sidecar exists because no approval layer applies to these kinds. zh/models/actor-private-effects.md section 2.1.
* event · object · $ref ./event-envelope.schema.json
Closed producer-signed Event. Shared persistent Events become final only when the current Realm governance Station issues a RealmCommit in the derived Realm, Circle, or Sidecar stream.
allOf · allOf[0] · ?
allOf · allOf[1] · ?
allOf · allOf[2] · ?
allOf · allOf[3] · ?
allOf · allOf[4] · ?
allOf · allOf[5] · $ref #/$defs/registered_admission_shape · $ref #/$defs/registered_admission_shape
allOf · allOf[6] · $ref #/$defs/registered_execution_shape · $ref #/$defs/registered_execution_shape
allOf · allOf[7] · ?
allOf · allOf[8] · ?
allOf · allOf[9] · ?
allOf · allOf[10] · ?
allOf · allOf[11] · ?
allOf · allOf[12] · ?
allOf · allOf[13] · ?
allOf · allOf[14] · ?
allOf · allOf[15] · ?
allOf · allOf[16] · ?
allOf · allOf[17] · ?
allOf · allOf[18] · ?
allOf · allOf[19] · ?
allOf · allOf[20] · ?
allOf · allOf[21] · ?
allOf · allOf[22] · ?
allOf · allOf[23] · ?
allOf · allOf[24] · ?
allOf · allOf[25] · ?
allOf · allOf[26] · ?
allOf · allOf[27] · ?
allOf · allOf[28] · ?
allOf · allOf[29] · ?
allOf · allOf[30] · ?
allOf · allOf[31] · ?
allOf · allOf[32] · ?
allOf · allOf[33] · ?
allOf · allOf[34] · ?
allOf · allOf[35] · ?
allOf · allOf[36] · ?
allOf · allOf[37] · ?
allOf · allOf[38] · ?
allOf · allOf[39] · ?
allOf · allOf[40] · ?
allOf · allOf[41] · ?
allOf · allOf[42] · ?
allOf · allOf[43] · ?
allOf · allOf[44] · ?
allOf · allOf[45] · ?
allOf · allOf[46] · ?
allOf · allOf[47] · ?
allOf · allOf[48] · ?
allOf · allOf[49] · ?
allOf · allOf[50] · ?
allOf · allOf[51] · ?
allOf · allOf[52] · ?
allOf · allOf[53] · ?
allOf · allOf[54] · ?
allOf · allOf[55] · ?
allOf · allOf[56] · ?
allOf · allOf[57] · ?
allOf · allOf[58] · ?
allOf · allOf[59] · ?
allOf · allOf[60] · ?
allOf · allOf[61] · ?
allOf · allOf[62] · ?
allOf · allOf[63] · ?
allOf · allOf[64] · ?
allOf · allOf[65] · ?
allOf · allOf[66] · ?
allOf · allOf[67] · ?
allOf · allOf[68] · ?
allOf · allOf[69] · ?
allOf · allOf[70] · ?
allOf · allOf[71] · ?
allOf · allOf[72] · ?
allOf · allOf[73] · ?
allOf · allOf[74] · ?
allOf · allOf[75] · ?
allOf · allOf[76] · ?
allOf · allOf[77] · ?
allOf · allOf[78] · ?
allOf · allOf[79] · ?
allOf · allOf[80] · ?
allOf · allOf[81] · ?
allOf · allOf[82] · ?
allOf · allOf[83] · ?
allOf · allOf[84] · ?
allOf · allOf[85] · ?
allOf · allOf[86] · ?
allOf · allOf[87] · ?
allOf · allOf[88] · ?
allOf · allOf[89] · ?
allOf · allOf[90] · ?
allOf · allOf[91] · ?
allOf · allOf[92] · ?
allOf · allOf[93] · ?
allOf · allOf[94] · ?
allOf · allOf[95] · ?
allOf · allOf[96] · ?
allOf · allOf[97] · ?
allOf · allOf[98] · ?
allOf · allOf[99] · ?
allOf · allOf[100] · ?
allOf · allOf[101] · ?
allOf · allOf[102] · ?
allOf · allOf[103] · ?
allOf · allOf[104] · ?
allOf · allOf[105] · ?
allOf · allOf[106] · ?
allOf · allOf[107] · ?
allOf · allOf[108] · ?
allOf · allOf[109] · ?
allOf · allOf[110] · ?
allOf · allOf[111] · ?
allOf · allOf[112] · ?
allOf · allOf[113] · ?
allOf · allOf[114] · ?
allOf · allOf[115] · ?
allOf · allOf[116] · ?
allOf · allOf[117] · ?
allOf · allOf[118] · ?
allOf · allOf[119] · ?
allOf · allOf[120] · ?
allOf · allOf[121] · ?
allOf · allOf[122] · ?
allOf · allOf[123] · ?
allOf · allOf[124] · ?
allOf · allOf[125] · ?
allOf · allOf[126] · ?
allOf · allOf[127] · ?
allOf · allOf[128] · ?
allOf · allOf[129] · ?
allOf · allOf[130] · ?
allOf · allOf[131] · ?
allOf · allOf[132] · ?
allOf · allOf[133] · ?
allOf · allOf[134] · ?
allOf · allOf[135] · ?
allOf · allOf[136] · ?
allOf · allOf[137] · ?
allOf · allOf[138] · ?
allOf · allOf[139] · ?
allOf · allOf[140] · ?
* event_id · string · $ref ./common-ids.schema.json#/$defs/event_id
Complete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern: ^ak:event:[A-Za-z0-9_-]{44}$
* kind · string
Standard ak.* Event kinds MUST appear in artifacts/registry/event-kind-registry.json. State convergence is defined by the registered pure reducer over kind + payload; producers do not submit typed current result writes.
pattern: ^ak\.[a-z0-9_]+(\.[a-z0-9_]+)*$
realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* scope_ref · $ref #/$defs/scope_ref · $ref #/$defs/scope_ref
Required producer-signed security scope. The closed union is ordinary existing realm, circle, or native sidecar scope plus the create-only realm_genesis exception. It enters proof.event_digest and E2EE AAD. Reducers independently derive the exact scope from schema-validated payload and accepted references; missing dependencies, nonexistent scope, realm_id mismatch, omitted sidecar_id, substituting circle for sidecar, or any unequal field is fail closed. Sidecar domain Event kinds remain Extension-owned; recognizing this native security shape does not make Kernel interpret the Sidecar reducer. Exact product targets remain inside recipient-visible ciphertext.
* actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind · const "account"
enum: "account"
* account_id · $ref #/$defs/account_id · $ref #/$defs/account_id
oneOf · oneOf[1] · object
* kind · const "service"
enum: "service"
* service_id · $ref #/$defs/did_core_id · $ref #/$defs/did_core_id
executed_by · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind · const "account"
enum: "account"
* account_id · $ref #/$defs/account_id · $ref #/$defs/account_id
oneOf · oneOf[1] · object
* kind · const "service"
enum: "service"
* service_id · $ref #/$defs/did_core_id · $ref #/$defs/did_core_id
authorization_ref · oneOf[6]
Optional. Required when executed_by is present. It identifies an accepted Grant, delegation Event, DID-document delegation, or one of the closed profile-specific authority constants. The current governance Station evaluates the reference against the target stream's committed state.
oneOf · oneOf[0] · $ref #/$defs/grant_ref · $ref #/$defs/grant_ref
oneOf · oneOf[1] · $ref #/$defs/event_ref · $ref #/$defs/event_ref
oneOf · oneOf[2] · $ref #/$defs/did_delegation_ref · $ref #/$defs/did_delegation_ref
oneOf · oneOf[3] · $ref #/$defs/direct_conversation_participant_authority_ref · $ref #/$defs/direct_conversation_participant_authority_ref
oneOf · oneOf[4] · $ref #/$defs/direct_conversation_bootstrap_authority_ref · $ref #/$defs/direct_conversation_bootstrap_authority_ref
oneOf · oneOf[5] · $ref #/$defs/membership_compensation_delegation_ref · $ref #/$defs/membership_compensation_delegation_ref
applet_id · $ref #/$defs/applet_id · $ref #/$defs/applet_id
Optional signed Applet provenance. Required by ak.profile.applet_* when the Event is introduced by an Applet, Ghost Actor, bridge, or delegated applet path. Enters canonical event bytes and therefore is covered by proof.event_digest. When present, authorization_ref MUST also be present and resolve to a real active registration/capability grant binding this applet_id, registration_epoch, action and resource per zh/extensions/applet-integration.md sections 4, 8 and 11. Service-actor self-signature proves provenance but is not an authorization substitute. Capability-gated actions require a grant covering action/resource. For subject_only operations the referenced grant binds only the exact active install and cannot replace the subject signature, FSM or independent action authority. Service self-authored Events use ActorId.service; the install grant subject MUST be the same exact ActorId.service as its producer; hosting Station and effective scope are verified separately without coercing a Service into an account variant.
external_ref · $ref #/$defs/external_ref · $ref #/$defs/external_ref
Optional signed external provenance reference for Applet / bridge-originated Events. It is covered by event_digest and MUST NOT be carried only in unsigned when used for loop prevention, audit, or external-message idempotency. Must not contain unauthorized external plaintext.
* created_at · $ref #/$defs/canonical_event_timestamp · $ref #/$defs/canonical_event_timestamp
semantic_refs · array<$ref #/$defs/semantic_ref>
Optional semantic refs with role. Omit when there are no semantic references; an explicitly empty array is not canonical. Admission selectors determine any required references. PCR policy recovery has no DID-root anchor reference; its policy/session/replacement-key authority is verified separately.
items · $ref #/$defs/semantic_ref · $ref #/$defs/semantic_ref
* payload · object
* producer_proof · $ref #/$defs/event_proof · $ref #/$defs/event_proof
The Event's sole portable producer proof. Storage receipts are separate objects and never authorize this Event. producer_proof and unsigned remain outside the canonical Event digest. Exact retries preserve the verified producer proof.
anyOf · anyOf[3] · object · $ref #/$defs/AccountCursorRevokeOutcome
* revoked · boolean
expires_at · string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
anyOf · anyOf[4] · object · $ref #/$defs/AccountCursorRevokeRequestBody
* cursor · string
pattern: ^ak:cursor:[A-Za-z0-9_-]+$
* reason_code · string
pattern: ^[a-z][a-z0-9_]{0,63}$
revoke_scope · string (enum)
enum: "this_cursor" "same_device" "same_session"
example: "this_cursor"
anyOf · anyOf[5] · object · $ref #/$defs/AccountLogoutOutcome
* revoked · boolean
Whether a live device session was revoked.
anyOf · anyOf[6] · object · $ref #/$defs/AccountLogoutRequestBody
anyOf · anyOf[7] · object · $ref #/$defs/AuthSessionLogoutOutcome
* grant_chain_terminated · boolean
Whether the grant rotation chain is now unable to refresh, including the already-terminated idempotent case.
* auth_session_logged_out · boolean
Whether the underlying Auth-side browser/auth session is now logged out, including the already-logged-out idempotent case.
anyOf · anyOf[8] · object · $ref #/$defs/AuthSessionLogoutRequestBody
Service-to-service Account Authority to Auth Server request that logs out the Auth-side session owning a ak.session.grant rotation chain.
* grant_jwt · string
Session grant used to locate the Auth-side session and its rotation chain.
logout_request_digest · string
Optional digest of the validated client-visible account /logout request that caused this S2S sub-operation.
pattern: ^(sha256|blake3):[0-9a-f]{64}$
validated_at · string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
reason_code · string (enum)
Reason for logging out the Auth-side session. v1 defines only account_logout for this S2S sub-operation.
enum: "account_logout"
anyOf · anyOf[9] · object · $ref #/$defs/AuthzCheckOutcome
ak.self.authz.read.check.v1 diagnostic/preflight decision. See zh/authz/capabilities.md §18. This response is advisory; canonical Event admission remains authoritative.
* decision · string (enum)
`allow` / `hard_deny` are terminal decisions. `soft_deny` is an evaluated policy soft refusal. `quarantine` / `require_review` are local moderation outcomes. Transient dependency or freshness failures are reported through `freshness_state`, `reason_code`, and `retry_after_ms`, not as policy decision values.
enum: "allow" "soft_deny" "hard_deny" "quarantine" "require_review"
matched_grants · array<object>
items · object
applied_constraints · array<object>
items · object
policy_results · array<object>
items · object
missing_proofs · array<object>
items · object
checkpoint · object
freshness_state · string (enum)
Checkpoint freshness classification for revocation-sensitive decisions; see zh/authz/capabilities.md §18.2.
enum: "fresh" "stale" "unknown"
last_known_checkpoint_age_ms · integer
Age of the newest revocation/auth checkpoint evidence used for this decision. Present when freshness_state is stale or unknown.
authority_status · string (enum)
Coarse status of the current governance Station and committed-stream source used to diagnose stale or unknown revocation freshness.
enum: "fresh" "lagging" "unreachable" "unknown"
cache_expires_at · string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
reason_code · string
Registered reason code. High-risk stale or unknown revocation freshness returns revocation_freshness_unknown.
pattern: ^[a-z][a-z0-9_]{0,63}$
retry_after_ms · integer
Set when `freshness_state ∈ {stale,unknown}` or a retryable `reason_code` is present; client SHOULD back off this amount before retry.
obligations · array<object>
Additional local preflight obligations the caller MUST satisfy before the action proceeds.
items · object
anyOf · anyOf[10] · object · $ref #/$defs/AuthzCheckRequestBody
ak.self.authz.read.check.v1 advisory local authorization preflight. It is never a cross-service authorization fact and cannot replace the current governance Station's admission decision.
* actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind · const "account"
enum: "account"
* account_id · $ref #/$defs/account_id · $ref #/$defs/account_id
oneOf · oneOf[1] · object
* kind · const "service"
enum: "service"
* service_id · $ref #/$defs/did_core_id · $ref #/$defs/did_core_id
* action · string
Capability action id (e.g. `ak.strand.update`).
resource · object
Optional resource selector (Realm / Strand / Space / Morph / etc.).
context · object
Optional decision context — claim presentations, checkpoint reference, request metadata.
anyOf · anyOf[11] · object · $ref #/$defs/BlobPresignOutcome
* url · string (uri) · format=uri
Fully-qualified URL clients can pass to browser primitives. Contains the `presign` query parameter, `blob_ref`, and a presign envelope bound to `realm_id` for Realm-owned blobs.
pattern: ^https?://
* expires_at · string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
purpose · string
Echo of the issued `purpose`.
anyOf · anyOf[12] · object · $ref #/$defs/BlobPresignRequestBody
* blob_ref · string · $ref ./common-ids.schema.json#/$defs/blob_ref
Content-addressed reference to exact Blob bytes. The embedded suite and digest are the sole wire commitment to those bytes; sibling content/ciphertext digest mirrors are forbidden.
pattern: ^ak:blob:(?:sha256|blake3):[0-9a-f]{64}$
realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
max_age_seconds · integer
Client-requested TTL upper bound. Server clamps to the smaller of this value, the issuing grant's `blob_presign_max_ttl_seconds` constraint, and the deployment-level cap.
purpose · string (enum)
Intended rendering / download mode. Servers MAY apply purpose-specific Content-Disposition or rate limits.
enum: "media_inline" "thumbnail" "download"
anyOf · anyOf[13] · object · $ref #/$defs/CallMediaTokenExchangeOutcome
allOf · allOf[0] · ?
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* call_id · string
pattern: ^ak:call:[A-Za-z0-9_-]{44}$
* actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind · const "account"
enum: "account"
* account_id · $ref #/$defs/account_id · $ref #/$defs/account_id
oneOf · oneOf[1] · object
* kind · const "service"
enum: "service"
* service_id · $ref #/$defs/did_core_id · $ref #/$defs/did_core_id
* device_id · string
pattern: ^ak:device:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$
* focus_id · string
pattern: ^(?!ak:)
* connect_url · string (uri) · format=uri
pattern: ^(https|wss)://
* backend_token · ?
Closed branch selected by backend_kind: arkret_native uses the typed signature object; every other v1 backend uses a non-empty opaque string.
* participant_id · string
SFU-local short handle, scope `(call_id, focus_id, sfu_did)`. UUIDv7-form rtc_participant typed ID.
pattern: ^ak:rtc_participant:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$
* participant_binding · object · $ref ./event-payload.schema.json#/$defs/participant_binding
Token issuer's signed commitment over (realm_id, call_id, focus_id, actor_id, device_id, participant_id, expires_at) for a media participant. See crypto-media/media-service-binding.md §3 and crypto-media/call-state.md §4.1. v1 uses the single scheme ak.media.participant_binding.v1.
* expires_at · $ref #/$defs/timestamp · $ref #/$defs/timestamp
* issuer_kid · string
DID URL (with fragment) of the token issuer service signing key. MUST resolve to a service DID present in the current-epoch ak.realm.media_service.service_id.
pattern: ^did:[a-z0-9]+:[^\s?]+#[^\s#?]+$
* sig · $ref #/$defs/non_empty_string · $ref #/$defs/non_empty_string
* expires_at · string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
* backend_kind · string (enum)
Backend binding type identifier (livekit / arkret_native / etc.).
enum: "livekit" "mediasoup" "janus" "arkret_native" "moq_relay"
anyOf · anyOf[14] · object · $ref #/$defs/CallMediaTokenExchangeRequestBody
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* call_id · string
pattern: ^ak:call:[A-Za-z0-9_-]{44}$
* actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind · const "account"
enum: "account"
* account_id · $ref #/$defs/account_id · $ref #/$defs/account_id
oneOf · oneOf[1] · object
* kind · const "service"
enum: "service"
* service_id · $ref #/$defs/did_core_id · $ref #/$defs/did_core_id
* device_id · string
Stable protocol endpoint identifier. REQUIRED for agent_key_proof and covered by request_canonical_digest; the Account Authority MUST persist and return the same value in the issued grant so Stations can bind MLS KeyPackage ownership, Welcome routing, consume/revoke operations, refresh, and restart recovery to one endpoint. It MUST NOT be derived from a session or grant id.
pattern: ^ak:device:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$
* focus_id · string
pattern: ^(?!ak:)
capability_refs · array<string>
items · string
pattern: ^ak:grant:[A-Za-z0-9_-]{44}$
desired_media · object
audio · boolean
video · boolean
screen · boolean
anyOf · anyOf[15] · object · $ref #/$defs/DeviceMessagesAckOutcome
* pruned_count · integer
Number of recipient deliveries acknowledged by this token: DeviceMessage rows deleted plus Welcome rows marked delivered and retained for audit; zero is legal for a repeated or older token.
anyOf · anyOf[16] · object · $ref #/$defs/DeviceMessagesAckRequestBody
* ack_token · string
Acknowledgement token previously issued to the same authenticated recipient endpoint by account subscribe or the recipient-delivery list. It cumulatively prunes both DeviceMessage and MlsWelcomeDelivery queue items through the bound position, only after every covered item was durably processed. Unknown / expired / cross-bound tokens MUST be rejected with param_invalid (reason invalid_ack_token) without deleting anything. Naturally idempotent; no Idempotency-Key required.
anyOf · anyOf[17] · object · $ref #/$defs/DeviceMessagesGetOutcome
allOf · allOf[0] · ?
* deliveries · array<$ref ./account-subscribe-frame.schema.json#/$defs/recipient_delivery>
Ordered recipient-private queue items, each discriminated as an unchanged DeviceMessageEnvelope or MlsWelcomeDelivery. These are not shared Event Envelope objects.
items · oneOf[2] · $ref ./account-subscribe-frame.schema.json#/$defs/recipient_delivery
One exact recipient-private queue item. The discriminator selects an unchanged DeviceMessageEnvelope or producer-signed MlsWelcomeDelivery; neither payload is rewritten into the other.
oneOf · oneOf[0] · object
* delivery_kind · const "device_message"
enum: "device_message"
* device_message · object · $ref ./device-message.schema.json
allOf · allOf[0] · ?
allOf · allOf[1] · oneOf[3]
oneOf · oneOf[0] · ?
oneOf · oneOf[1] · ?
oneOf · oneOf[2] · ?
allOf · allOf[2] · ?
allOf · allOf[3] · ?
* device_message_id · $ref #/$defs/device_message_id · $ref #/$defs/device_message_id
Sender-assigned stable identity of one logical to-device message. Queue services MUST preserve it byte-for-byte across retries and redelivery. Receivers deduplicate by the exact closed sender identity and device_message_id: (sender_account_id, sender_device_id, device_message_id), (sender_agent_id, device_message_id), or (sender_id, device_message_id).
* kind · string
pattern: ^ak\.[a-z0-9_]+(\.[a-z0-9_]+)*$
sender_account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id · $ref #/$defs/did_core_id · $ref #/$defs/did_core_id
* station_id · $ref #/$defs/did_core_id · $ref #/$defs/did_core_id
sender_device_id · $ref #/$defs/device_id · $ref #/$defs/device_id
Authoring human device. Exactly one sender endpoint branch is present: sender_account_id plus this field, the complete sender_agent_* triple, or sender_id. An Agent runtime has no device identity and MUST NOT be disguised as an ak:device; the restricted Station materializer likewise has a service identity rather than a fake device.
sender_agent_id · $ref #/$defs/did_core_id · $ref #/$defs/did_core_id
Agent principal that authored this message. Present exactly when the sender is an Agent runtime, together with sender_agent_verification_method and sender_agent_key_authorize_event_id. It is the sole Agent identity carrier.
sender_agent_verification_method · string · $ref ./common-ids.schema.json#/$defs/did_url
Arkret verification-method DID URL profile (identity/did-usage-and-verification.md section 2.2): lowercase method name, no query, required fragment, fragment limited to ASCII [A-Za-z0-9._:-]. Every verification_method-family field and every kid/key_ref a schema declares to be a DID URL MUST resolve to exactly this definition; values compare byte-for-byte with no URI normalization or percent-decoding.
pattern: ^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$
sender_agent_key_authorize_event_id · string · $ref ./common-ids.schema.json#/$defs/event_id
Complete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern: ^ak:event:[A-Za-z0-9_-]{44}$
sender_id · $ref #/$defs/did_core_id · $ref #/$defs/did_core_id
Station service identity that internally materialized an actor-private update for the holder. This branch is restricted to actor_private_update_kind, and sender_id MUST equal recipient_account_id.station_id and the Station identity bound to the recipient's current authenticated self/to-device surface. It is not a bearer delegation and cannot be submitted through ak.self.device_messages.command.send.v1.
* recipient_account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id · $ref #/$defs/did_core_id · $ref #/$defs/did_core_id
* station_id · $ref #/$defs/did_core_id · $ref #/$defs/did_core_id
* recipient_device_id · $ref #/$defs/device_id · $ref #/$defs/device_id
* sent_at · $ref #/$defs/timestamp · $ref #/$defs/timestamp
* expires_at · $ref #/$defs/timestamp · $ref #/$defs/timestamp
* content · object
unsigned · object
Optional non-authenticated metadata block (transport-layer hints only). Receivers MUST NOT trust any field here for authorization, ordering, or cryptographic verification. Typical sub-fields: progress (delivery progress hint), error_context (transport-layer error diagnostics), retry_after_ms. By convention this block is excluded from the signed transcript of the enclosing transport envelope and is dropped on persist.
oneOf · oneOf[1] · object
* delivery_kind · const "mls_welcome"
enum: "mls_welcome"
* mls_welcome · object · $ref ./mls-welcome-delivery.schema.json
Producer-signed recipient delivery queued atomically with its winning MLS Commit. This is not a shared Realm Event and does not receive an independent RealmCommit.
* welcome_id · string · $ref ./common-ids.schema.json#/$defs/mls_welcome_delivery_id
pattern: ^ak:mls_welcome_delivery:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* effective_scope · oneOf[4] · $ref ./event-envelope.schema.json#/$defs/scope_ref
oneOf · oneOf[0] · object
* kind · const "realm"
enum: "realm"
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
oneOf · oneOf[1] · object
* kind · const "circle"
enum: "circle"
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* circle_id · string · $ref ./common-ids.schema.json#/$defs/circle_id
pattern: ^ak:circle:[A-Za-z0-9_-]{44}$
oneOf · oneOf[2] · object
Native controller-and-owned-Agents private scope. It is not a Circle and has no editable membership.
* kind · const "sidecar"
enum: "sidecar"
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* sidecar_id · string · $ref ./common-ids.schema.json#/$defs/sidecar_id
pattern: ^ak:sidecar:[A-Za-z0-9_-]{44}$
oneOf · oneOf[3] · object
Genesis scope for ak.realm.create only. It carries no realm_id because the receiver derives every Realm id, including Collaboration, Direct Conversation, human PCR, and Agent PCR, as retype(event_id, "realm") from this create Event (zh/models/realm-and-space.md section 2.5.0). The uniform omission also prevents the digest cycle.
* kind · const "realm_genesis"
enum: "realm_genesis"
* commit_event_ref · string · $ref ./common-ids.schema.json#/$defs/event_id
Complete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern: ^ak:event:[A-Za-z0-9_-]{44}$
* recipient_actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind · const "account"
enum: "account"
* account_id · $ref #/$defs/account_id · $ref #/$defs/account_id
oneOf · oneOf[1] · object
* kind · const "service"
enum: "service"
* service_id · $ref #/$defs/did_core_id · $ref #/$defs/did_core_id
* recipient_endpoint · oneOf[2]
oneOf · oneOf[0] · object
* kind · const "device"
enum: "device"
* device_id · string · $ref ./common-ids.schema.json#/$defs/device_id
pattern: ^ak:device:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$
oneOf · oneOf[1] · object
* kind · const "agent_runtime"
enum: "agent_runtime"
* verification_method · string · $ref ./common-ids.schema.json#/$defs/did_url
Arkret verification-method DID URL profile (identity/did-usage-and-verification.md section 2.2): lowercase method name, no query, required fragment, fragment limited to ASCII [A-Za-z0-9._:-]. Every verification_method-family field and every kid/key_ref a schema declares to be a DID URL MUST resolve to exactly this definition; values compare byte-for-byte with no URI normalization or percent-decoding.
pattern: ^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$
* keypackage_claim_ref · string
pattern: ^ak:keypackage_claim:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$
* ciphertext_b64 · string
pattern: ^[A-Za-z0-9_-]+$
* producer_proof · allOf[2] · $ref ./detached-object-signature.schema.json#/$defs/mls_welcome_delivery_signature
allOf · allOf[0] · anyOf[61] · $ref #
Canonical DTOs reachable from current authority-commit operations. Every definition is part of the current operation closure.
anyOf · anyOf[0] · object · $ref #/$defs/AcceptedDevicePossessionProof
Accepted-device Ed25519 possession proof shared by human SessionGrant issue and refresh. The signature covers utf8('ak.session_grant_accepted_device_possession_proof.v1\n') followed by RFC 8785 JCS of this complete object with signature omitted. It is not a server challenge: freshness comes from the <=300 second signed window, the one-time account handoff or predecessor grant, the issuer request identity, and issuer-ledger exact replay. The origin Station MUST verify this proof with the durable current accepted-device key in the same linearization that evaluates current authorization.
allOf · allOf[0] · …
recursion truncated at depth 8; see source schema for full shape
* context · …
recursion truncated at depth 8; see source schema for full shape
* purpose · …
recursion truncated at depth 8; see source schema for full shape
request_id · …
recursion truncated at depth 8; see source schema for full shape
account_subject · …
recursion truncated at depth 8; see source schema for full shape
account_handoff_grant_digest · …
recursion truncated at depth 8; see source schema for full shape
predecessor_session_grant_id · …
recursion truncated at depth 8; see source schema for full shape
* account_id · …
recursion truncated at depth 8; see source schema for full shape
* device_id · …
recursion truncated at depth 8; see source schema for full shape
* audience_id · …
recursion truncated at depth 8; see source schema for full shape
* holder_jkt · …
recursion truncated at depth 8; see source schema for full shape
* session_intent_digest · …
recursion truncated at depth 8; see source schema for full shape
* issued_at · …
recursion truncated at depth 8; see source schema for full shape
* expires_at · …
recursion truncated at depth 8; see source schema for full shape
* verification_method · …
recursion truncated at depth 8; see source schema for full shape
* signature · …
recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[1] · oneOf[2] · $ref #/$defs/ActorPrivateEventSubmitOutcome
Closed outcome of ak.self.actor_private_events.command.submit.v1, discriminated by event_kind. accepted_event_id is the event_id of the accepted Event, and an exact retry returns the first stored outcome. Only ak.device.push_route carries the accepted per-route revision its next write must name as expected_server_revision. No RealmCommit exists for these writes.
oneOf · oneOf[0] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · …
recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[2] · object · $ref #/$defs/ActorPrivateEventSubmitRequestBody
Request of ak.self.actor_private_events.command.submit.v1: exactly one caller-signed actor-private Event of a kind that has no dedicated submit operation. The service validates the exact Event bytes and MUST NOT rebuild the payload or co-sign. No approval sidecar exists because no approval layer applies to these kinds. zh/models/actor-private-effects.md section 2.1.
* event · …
recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[3] · object · $ref #/$defs/AccountCursorRevokeOutcome
* revoked · …
recursion truncated at depth 8; see source schema for full shape
expires_at · …
recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[4] · object · $ref #/$defs/AccountCursorRevokeRequestBody
* cursor · …
recursion truncated at depth 8; see source schema for full shape
* reason_code · …
recursion truncated at depth 8; see source schema for full shape
revoke_scope · …
recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[5] · object · $ref #/$defs/AccountLogoutOutcome
* revoked · …
recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[6] · object · $ref #/$defs/AccountLogoutRequestBody
anyOf · anyOf[7] · object · $ref #/$defs/AuthSessionLogoutOutcome
* grant_chain_terminated · …
recursion truncated at depth 8; see source schema for full shape
* auth_session_logged_out · …
recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[8] · object · $ref #/$defs/AuthSessionLogoutRequestBody
Service-to-service Account Authority to Auth Server request that logs out the Auth-side session owning a ak.session.grant rotation chain.
* grant_jwt · …
recursion truncated at depth 8; see source schema for full shape
logout_request_digest · …
recursion truncated at depth 8; see source schema for full shape
validated_at · …
recursion truncated at depth 8; see source schema for full shape
reason_code · …
recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[9] · object · $ref #/$defs/AuthzCheckOutcome
ak.self.authz.read.check.v1 diagnostic/preflight decision. See zh/authz/capabilities.md §18. This response is advisory; canonical Event admission remains authoritative.
* decision · …
recursion truncated at depth 8; see source schema for full shape
matched_grants · …
recursion truncated at depth 8; see source schema for full shape
applied_constraints · …
recursion truncated at depth 8; see source schema for full shape
policy_results · …
recursion truncated at depth 8; see source schema for full shape
missing_proofs · …
recursion truncated at depth 8; see source schema for full shape
checkpoint · …
recursion truncated at depth 8; see source schema for full shape
freshness_state · …
recursion truncated at depth 8; see source schema for full shape
last_known_checkpoint_age_ms · …
recursion truncated at depth 8; see source schema for full shape
authority_status · …
recursion truncated at depth 8; see source schema for full shape
cache_expires_at · …
recursion truncated at depth 8; see source schema for full shape
reason_code · …
recursion truncated at depth 8; see source schema for full shape
retry_after_ms · …
recursion truncated at depth 8; see source schema for full shape
obligations · …
recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[10] · object · $ref #/$defs/AuthzCheckRequestBody
ak.self.authz.read.check.v1 advisory local authorization preflight. It is never a cross-service authorization fact and cannot replace the current governance Station's admission decision.
* actor_id · …
recursion truncated at depth 8; see source schema for full shape
* action · …
recursion truncated at depth 8; see source schema for full shape
resource · …
recursion truncated at depth 8; see source schema for full shape
context · …
recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[11] · object · $ref #/$defs/BlobPresignOutcome
* url · …
recursion truncated at depth 8; see source schema for full shape
* expires_at · …
recursion truncated at depth 8; see source schema for full shape
purpose · …
recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[12] · object · $ref #/$defs/BlobPresignRequestBody
* blob_ref · …
recursion truncated at depth 8; see source schema for full shape
realm_id · …
recursion truncated at depth 8; see source schema for full shape
max_age_seconds · …
recursion truncated at depth 8; see source schema for full shape
purpose · …
recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[13] · object · $ref #/$defs/CallMediaTokenExchangeOutcome
allOf · allOf[0] · …
recursion truncated at depth 8; see source schema for full shape
* realm_id · …
recursion truncated at depth 8; see source schema for full shape
* call_id · …
recursion truncated at depth 8; see source schema for full shape
* actor_id · …
recursion truncated at depth 8; see source schema for full shape
* device_id · …
recursion truncated at depth 8; see source schema for full shape
* focus_id · …
recursion truncated at depth 8; see source schema for full shape
* connect_url · …
recursion truncated at depth 8; see source schema for full shape
* backend_token · …
recursion truncated at depth 8; see source schema for full shape
* participant_id · …
recursion truncated at depth 8; see source schema for full shape
* participant_binding · …
recursion truncated at depth 8; see source schema for full shape
* expires_at · …
recursion truncated at depth 8; see source schema for full shape
* backend_kind · …
recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[14] · object · $ref #/$defs/CallMediaTokenExchangeRequestBody
* realm_id · …
recursion truncated at depth 8; see source schema for full shape
* call_id · …
recursion truncated at depth 8; see source schema for full shape
* actor_id · …
recursion truncated at depth 8; see source schema for full shape
* device_id · …
recursion truncated at depth 8; see source schema for full shape
* focus_id · …
recursion truncated at depth 8; see source schema for full shape
capability_refs · …
recursion truncated at depth 8; see source schema for full shape
desired_media · …
recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[15] · object · $ref #/$defs/DeviceMessagesAckOutcome
* pruned_count · …
recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[16] · object · $ref #/$defs/DeviceMessagesAckRequestBody
* ack_token · …
recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[17] · object · $ref #/$defs/DeviceMessagesGetOutcome
allOf · allOf[0] · …
recursion truncated at depth 8; see source schema for full shape
* deliveries · …
recursion truncated at depth 8; see source schema for full shape
ack_token · …
recursion truncated at depth 8; see source schema for full shape
next_cursor · …
recursion truncated at depth 8; see source schema for full shape
* has_more · …
recursion truncated at depth 8; see source schema for full shape
limited · …
recursion truncated at depth 8; see source schema for full shape
lost · …
recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[18] · object · $ref #/$defs/DeviceMessagesSendOutcome
* delivered · …
recursion truncated at depth 8; see source schema for full shape
* unknown_devices · …
recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[19] · object · $ref #/$defs/DeviceMessagesSendRequestBody
* messages · …
recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[20] · object · $ref #/$defs/DidOperationSubmitOutcome
* status · …
recursion truncated at depth 8; see source schema for full shape
* did · …
recursion truncated at depth 8; see source schema for full shape
* accepted_at · …
recursion truncated at depth 8; see source schema for full shape
seq · …
recursion truncated at depth 8; see source schema for full shape
* operation_ref · …
recursion truncated at depth 8; see source schema for full shape
receipts · …
recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[21] · object · $ref #/$defs/DidOperationSubmitRequestBody
* did · …
recursion truncated at depth 8; see source schema for full shape
* did_method · …
recursion truncated at depth 8; see source schema for full shape
seq · …
recursion truncated at depth 8; see source schema for full shape
prev_event_digest · …
recursion truncated at depth 8; see source schema for full shape
* operation · …
recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[22] · oneOf[2] · $ref #/$defs/DirectConversationFoundingAuthorityEvidence
Closed XOR authorization evidence for one Direct Conversation founding unit, matching the two registered ak.realm.create admission variants. The human branch feeds direct_conversation_genesis; the controller_agent branch feeds direct_conversation_agent_genesis. Carrying both, neither, or mixed branch fields rejects the whole unit.
oneOf · oneOf[0] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · …
recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[23] · object · $ref #/$defs/EventAdmissionSubmission
One exact producer-signed Event submitted to the current governance Station, plus the approval signatures required by a grant, Realm governance or List WIP policy for the Event action or for this registered submit operation. There are no RealmCommit, typed current result, offline-lease or proof-bundle sidecars. approval_signatures is the only sidecar and it is deliberately outside event: the Event bytes and event_id are finished before any approval is signed, so attaching them never changes the Event (zh/authz/constraint-schema.md section 9.2.5).
* event · …
recursion truncated at depth 8; see source schema for full shape
approval_signatures · …
recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[24] · object · $ref #/$defs/EventDeliveryStatusOutcome
Complete frozen target set for one visible Event. Rows are sorted byte-wise by unique opaque target_id. Consumers derive the pending count by counting pending_route and pending_delivery rows, and derive aggregate state as pending iff that count is non-zero.
* event_id · …
recursion truncated at depth 8; see source schema for full shape
* targets · …
recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[25] · object · $ref #/$defs/EventDeliveryStatusRequestBody
Authenticated, non-enumerating request for the durable fanout state of one caller-visible accepted Event.
* event_id · …
recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[26] · object · $ref #/$defs/EventSubmitEnvelope
Closed producer-signed Event. Shared persistent Events become final only when the current Realm governance Station issues a RealmCommit in the derived Realm, Circle, or Sidecar stream.
allOf · allOf[0] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[2] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[3] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[4] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[5] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[6] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[7] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[8] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[9] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[10] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[11] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[12] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[13] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[14] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[15] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[16] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[17] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[18] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[19] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[20] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[21] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[22] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[23] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[24] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[25] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[26] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[27] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[28] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[29] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[30] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[31] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[32] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[33] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[34] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[35] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[36] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[37] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[38] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[39] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[40] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[41] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[42] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[43] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[44] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[45] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[46] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[47] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[48] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[49] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[50] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[51] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[52] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[53] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[54] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[55] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[56] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[57] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[58] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[59] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[60] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[61] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[62] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[63] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[64] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[65] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[66] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[67] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[68] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[69] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[70] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[71] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[72] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[73] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[74] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[75] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[76] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[77] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[78] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[79] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[80] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[81] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[82] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[83] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[84] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[85] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[86] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[87] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[88] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[89] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[90] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[91] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[92] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[93] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[94] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[95] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[96] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[97] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[98] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[99] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[100] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[101] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[102] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[103] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[104] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[105] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[106] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[107] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[108] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[109] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[110] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[111] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[112] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[113] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[114] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[115] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[116] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[117] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[118] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[119] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[120] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[121] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[122] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[123] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[124] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[125] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[126] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[127] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[128] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[129] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[130] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[131] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[132] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[133] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[134] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[135] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[136] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[137] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[138] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[139] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[140] · …
recursion truncated at depth 8; see source schema for full shape
* event_id · …
recursion truncated at depth 8; see source schema for full shape
* kind · …
recursion truncated at depth 8; see source schema for full shape
realm_id · …
recursion truncated at depth 8; see source schema for full shape
* scope_ref · …
recursion truncated at depth 8; see source schema for full shape
* actor_id · …
recursion truncated at depth 8; see source schema for full shape
executed_by · …
recursion truncated at depth 8; see source schema for full shape
authorization_ref · …
recursion truncated at depth 8; see source schema for full shape
applet_id · …
recursion truncated at depth 8; see source schema for full shape
external_ref · …
recursion truncated at depth 8; see source schema for full shape
* created_at · …
recursion truncated at depth 8; see source schema for full shape
semantic_refs · …
recursion truncated at depth 8; see source schema for full shape
* payload · …
recursion truncated at depth 8; see source schema for full shape
* producer_proof · …
recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[27] · object · $ref #/$defs/EventsSubmitBatchRequestBody
Legacy-named typed array retained only as the nested prepared_event_unit request in security-transaction.schema.json. It is not an ak.self.events.command.submit.v1 request: that operation accepts only authority-commit-operations.schema.json#/$defs/self_submit_request, including its closed ordinary_realm_bootstrap branch. The parent security transaction fixes the recovery unit type, slot count, order and authorization; this array alone grants no generic Event batch admission.
* events · …
recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[28] · object · $ref #/$defs/GrantList
Atomic subject-visible snapshot of active effective grants. Each row carries its own exact current-result revision; state_digest authenticates the list as a whole and is never a per-grant CAS operand.
* grants · …
recursion truncated at depth 8; see source schema for full shape
* state_digest · …
recursion truncated at depth 8; see source schema for full shape
* evaluated_at · …
recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[29] · object · $ref #/$defs/IdentityDocumentView
Result of ak.root.identity.document.resource.get.v1 — current DID Document plus normalized view hints.
* did_document · …
recursion truncated at depth 8; see source schema for full shape
normalized_view · …
recursion truncated at depth 8; see source schema for full shape
method_evidence · …
recursion truncated at depth 8; see source schema for full shape
cached_at · …
recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[30] · object · $ref #/$defs/IdentityLogListOutcome
Result of ak.root.identity.log.read.list.v1. Entries are returned in the DID method's own native log form: for did:webvh each entry is a verbatim did.jsonl log entry with its native versionId, entryHash chain and Data Integrity proof. Arkret defines no parallel entry envelope, sequence numbering, hash chain or proof transcript over DID logs — the method already provides all of them, and a second signed representation of the same history could disagree with the first. Methods without a native history (did:web) MUST report that rather than being wrapped in a shape that implies one.
* did · …
recursion truncated at depth 8; see source schema for full shape
* method · …
recursion truncated at depth 8; see source schema for full shape
native_history · …
recursion truncated at depth 8; see source schema for full shape
* entries · …
recursion truncated at depth 8; see source schema for full shape
next_cursor · …
recursion truncated at depth 8; see source schema for full shape
* has_more · …
recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[31] · object · $ref #/$defs/IdentityReceiptListOutcome
Result of ak.root.identity.receipts.read.list.v1. receipts[] is a tagged union over two distinct object families discriminated by their schema constant: ak.schema.identity_receipt.v1 records a role inside a DID registry consensus group (writer / witness / replica) and binds seq + accepted_entry_digest, while ak.schema.did_webvh_witness_receipt.v1 records a did:webvh method witness observed at a specific versionId. The two say different things with the same English word, so the discriminator is mandatory and a verifier MUST branch on it rather than infer intent from which optional fields happen to be present.
* receipts · …
recursion truncated at depth 8; see source schema for full shape
threshold_met · …
recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[32] · object · $ref #/$defs/IdentityResolveOutcome
did_document · …
recursion truncated at depth 8; see source schema for full shape
key_log_head · …
recursion truncated at depth 8; see source schema for full shape
seq · …
recursion truncated at depth 8; see source schema for full shape
method_evidence · …
recursion truncated at depth 8; see source schema for full shape
receipts · …
recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[33] · object · $ref #/$defs/IdentityResolveRequestBody
* did · …
recursion truncated at depth 8; see source schema for full shape
requested_evidence_kinds · …
recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[34] · object · $ref #/$defs/InitialSessionGrantIntent
Initial Standard SessionGrant intent embedded in identity_creation registration. It reuses the DPoP holder key established by account handoff; Account Authority recomputes RFC 7638 thumbprint of session_public_key and requires equality with the handoff/control-proof dpop_jkt. It is not a separate authorization or credential.
* device_id · …
recursion truncated at depth 8; see source schema for full shape
* session_public_key · …
recursion truncated at depth 8; see source schema for full shape
* audience_id · …
recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[35] · object · $ref #/$defs/MlsGroupStateMaterialOutcome
Exact RFC 9420 public group-state material. *_bytes_b64 use unpadded base64url. Consumers MUST decode each content-addressed Blob ref's embedded suite, hash the raw bytes under that suite, compare the digest, verify GroupInfo and ratchet_tree consistency, then derive leaf_index only from occupied leaves in the verified tree. Blob suites are independent of the fixed SHA-256 Event/RealmCommit identity suite.
* realm_id · …
recursion truncated at depth 8; see source schema for full shape
* effective_scope · …
recursion truncated at depth 8; see source schema for full shape
* mls_group_id · …
recursion truncated at depth 8; see source schema for full shape
* epoch · …
recursion truncated at depth 8; see source schema for full shape
* group_state_event_id · …
recursion truncated at depth 8; see source schema for full shape
* group_info_ref · …
recursion truncated at depth 8; see source schema for full shape
* group_info_bytes_b64 · …
recursion truncated at depth 8; see source schema for full shape
* ratchet_tree_ref · …
recursion truncated at depth 8; see source schema for full shape
* ratchet_tree_bytes_b64 · …
recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[36] · object · $ref #/$defs/MlsGroupStateMaterialRequestBody
Read-only service request for the exact public MLS epoch-0 GroupInfo and ratchet_tree bytes committed by one accepted ak.mls.genesis Event. Every Genesis selector is copied from that Event. When caller_actor_id is present, target_commit_event_ref and target_epoch are mandatory; governance checks current and target-cut member/history authority and source Station replication right at the target accepted Commit cut. Without caller_actor_id this remains the original Station replication-only read, with source Station replication right checked at the Genesis Commit position.
* realm_id · …
recursion truncated at depth 8; see source schema for full shape
* effective_scope · …
recursion truncated at depth 8; see source schema for full shape
* mls_group_id · …
recursion truncated at depth 8; see source schema for full shape
* epoch · …
recursion truncated at depth 8; see source schema for full shape
* group_state_event_id · …
recursion truncated at depth 8; see source schema for full shape
caller_actor_id · …
recursion truncated at depth 8; see source schema for full shape
target_commit_event_ref · …
recursion truncated at depth 8; see source schema for full shape
target_epoch · …
recursion truncated at depth 8; see source schema for full shape
* group_info_ref · …
recursion truncated at depth 8; see source schema for full shape
* ratchet_tree_ref · …
recursion truncated at depth 8; see source schema for full shape
max_response_bytes · …
recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[37] · object · $ref #/$defs/ModerationReportOutcome
* report_id · …
recursion truncated at depth 8; see source schema for full shape
routed_to_ids · …
recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[38] · object · $ref #/$defs/OrganizationRegistrationChallenge
Single-use control challenge. Every binding field exists to close one replay path: purpose separates this proof from any other signature the organization makes, audience and trust_domain pin it to this deployment, origin pins the HTTP surface, nonce makes it unrepeatable, and the expiry window bounds how long a captured proof stays useful. A registry MUST consume the challenge on the first successful use and atomically persist (challenge_id, canonical_request_digest, outcome). Only a byte-identical retry may return that stored outcome; the same challenge with any different digest is invalid.
* challenge_id · …
recursion truncated at depth 8; see source schema for full shape
* organization_id · …
recursion truncated at depth 8; see source schema for full shape
* organization_did · …
recursion truncated at depth 8; see source schema for full shape
* purpose · …
recursion truncated at depth 8; see source schema for full shape
* nonce · …
recursion truncated at depth 8; see source schema for full shape
* audience_id · …
recursion truncated at depth 8; see source schema for full shape
* origin · …
recursion truncated at depth 8; see source schema for full shape
* trust_domain · …
recursion truncated at depth 8; see source schema for full shape
* local_admin_subject_id · …
recursion truncated at depth 8; see source schema for full shape
* requested_scopes · …
recursion truncated at depth 8; see source schema for full shape
* expires_at · …
recursion truncated at depth 8; see source schema for full shape
* created_at · …
recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[39] · object · $ref #/$defs/OrganizationRegistrationChallengeRequestBody
Request a single-use control challenge for an external Organization DID. Two phases are mandatory: the registry issues the challenge and remembers it, then the caller proves control against it. Folding this into ensure would let the caller supply its own challenge, at which point neither freshness nor single use can be established by the receiver.
* organization_id · …
recursion truncated at depth 8; see source schema for full shape
* organization_did · …
recursion truncated at depth 8; see source schema for full shape
* local_admin_subject_id · …
recursion truncated at depth 8; see source schema for full shape
* requested_scopes · …
recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[40] · object · $ref #/$defs/OrganizationRegistrationEnsureRequestBody
Register an external Organization identity with this deployment by submitting both its stable organization_id core and current published organization_did. Idempotent on organization_id: replaying the same registration returns the existing binding with created=false. This operation registers a reference and a local administrative binding; it does not host the DID's method history, does not make this deployment its controller, and does not create Realm state.
* organization_id · …
recursion truncated at depth 8; see source schema for full shape
* organization_did · …
recursion truncated at depth 8; see source schema for full shape
* challenge_id · …
recursion truncated at depth 8; see source schema for full shape
* version_id · …
recursion truncated at depth 8; see source schema for full shape
* log_head_digest · …
recursion truncated at depth 8; see source schema for full shape
* control_proof · …
recursion truncated at depth 8; see source schema for full shape
* local_admin_subject_id · …
recursion truncated at depth 8; see source schema for full shape
* requested_scopes · …
recursion truncated at depth 8; see source schema for full shape
handle_attestation · …
recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[41] · object · $ref #/$defs/OrganizationRegistrationOutcome
Result of every organization registration command and of the read surface. Identity, DID, generation and version are read from the signed registration_receipt. created is true exactly on a call that opened a new generation.
* registration_receipt · …
recursion truncated at depth 8; see source schema for full shape
* created · …
recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[42] · object · $ref #/$defs/OrganizationRegistrationRefreshRequestBody
Re-prove control at a newer resolved version and re-issue the receipt. Scopes are not re-negotiated here; a scope change is a new ensure. Refresh exists because a binding pinned to one version stops proving current control the moment the organization rotates its controller.
* organization_id · …
recursion truncated at depth 8; see source schema for full shape
* organization_did · …
recursion truncated at depth 8; see source schema for full shape
* challenge_id · …
recursion truncated at depth 8; see source schema for full shape
* version_id · …
recursion truncated at depth 8; see source schema for full shape
* log_head_digest · …
recursion truncated at depth 8; see source schema for full shape
* control_proof · …
recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[43] · object · $ref #/$defs/OrganizationRegistrationRevokeRequestBody
Withdraw the local binding. This is a local act with local effect only: it does not modify, deactivate or annotate the external DID's method history, which this deployment does not control.
* organization_id · …
recursion truncated at depth 8; see source schema for full shape
reason_code · …
recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[44] · object · $ref #/$defs/ProjectionMorphList
* realm_id · …
recursion truncated at depth 8; see source schema for full shape
* morphs · …
recursion truncated at depth 8; see source schema for full shape
* total · …
recursion truncated at depth 8; see source schema for full shape
next_cursor · …
recursion truncated at depth 8; see source schema for full shape
* has_more · …
recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[45] · object · $ref #/$defs/ProjectionSpaceList
* realm_id · …
recursion truncated at depth 8; see source schema for full shape
* spaces · …
recursion truncated at depth 8; see source schema for full shape
* total · …
recursion truncated at depth 8; see source schema for full shape
next_cursor · …
recursion truncated at depth 8; see source schema for full shape
* has_more · …
recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[46] · object · $ref #/$defs/ProjectionStrandList
* realm_id · …
recursion truncated at depth 8; see source schema for full shape
* strands · …
recursion truncated at depth 8; see source schema for full shape
* total · …
recursion truncated at depth 8; see source schema for full shape
next_cursor · …
recursion truncated at depth 8; see source schema for full shape
* has_more · …
recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[47] · object · $ref #/$defs/StrandWatchCurrentRequestBody
Exact self watch selector. It cannot enumerate watchers or supply an expected CAS value.
* realm_id · …
recursion truncated at depth 8; see source schema for full shape
* strand_id · …
recursion truncated at depth 8; see source schema for full shape
* watcher_actor_id · …
recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[48] · oneOf[2] · $ref #/$defs/StrandWatchCurrentOutcome
A verified never-written fact is distinct from a written result whose value was cleared to null.
oneOf · oneOf[0] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · …
recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[49] · object · $ref #/$defs/ServiceRegistrationEnsureRequestBody
* service_kind · …
recursion truncated at depth 8; see source schema for full shape
* public_base_url · …
recursion truncated at depth 8; see source schema for full shape
* did · …
recursion truncated at depth 8; see source schema for full shape
* inception_operation · …
recursion truncated at depth 8; see source schema for full shape
* idempotency_key · …
recursion truncated at depth 8; see source schema for full shape
previous_receipt · …
recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[50] · object · $ref #/$defs/ServiceRegistrationOutcome
* did_document · …
recursion truncated at depth 8; see source schema for full shape
* registration_receipt · …
recursion truncated at depth 8; see source schema for full shape
* created · …
recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[51] · object · $ref #/$defs/SessionGrantIntrospectOutcome
allOf · allOf[0] · …
recursion truncated at depth 8; see source schema for full shape
* active · …
recursion truncated at depth 8; see source schema for full shape
* status · …
recursion truncated at depth 8; see source schema for full shape
* proof_required · …
recursion truncated at depth 8; see source schema for full shape
* one_time_use_consumed · …
recursion truncated at depth 8; see source schema for full shape
grant · …
recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[52] · object · $ref #/$defs/SessionGrantIntrospectRequestBody
Server-to-server session-grant introspection request. Exactly one of id / grant_jwt identifies the grant.
oneOf · oneOf[0] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · …
recursion truncated at depth 8; see source schema for full shape
id · …
recursion truncated at depth 8; see source schema for full shape
grant_jwt · …
recursion truncated at depth 8; see source schema for full shape
audience_id · …
recursion truncated at depth 8; see source schema for full shape
proof · …
recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[53] · object · $ref #/$defs/SessionGrantOutcome
* account_id · …
recursion truncated at depth 8; see source schema for full shape
device_id · …
recursion truncated at depth 8; see source schema for full shape
* session_grant · …
recursion truncated at depth 8; see source schema for full shape
* expires_at · …
recursion truncated at depth 8; see source schema for full shape
* session_grant_id · …
recursion truncated at depth 8; see source schema for full shape
* session_public_key · …
recursion truncated at depth 8; see source schema for full shape
* audience_id · …
recursion truncated at depth 8; see source schema for full shape
* granted_scope · …
recursion truncated at depth 8; see source schema for full shape
previous_session_grant_id · …
recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[54] · oneOf[2] · $ref #/$defs/SessionGrantRefreshRequestBody
Closed human-versus-Agent SessionGrant rotation union. Neither branch accepts a client-generated challenge or a generic proof_kind enum.
oneOf · oneOf[0] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · …
recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[55] · object · $ref #/$defs/SessionGrantReplayExpiredProblem
Closed RFC 9457 Problem Details extension members for session_grant_replay_expired. The named issuer-ledger record remains authoritative and no replacement grant is created under the same request identity.
* session_grant_id · …
recursion truncated at depth 8; see source schema for full shape
* state · …
recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[56] · object · $ref #/$defs/SessionGrantReplayTerminalProblem
Closed RFC 9457 Problem Details extension members for session_grant_replay_terminal. The state is an exact durable issuer-ledger terminal state and no replacement grant is created under the same request identity.
* session_grant_id · …
recursion truncated at depth 8; see source schema for full shape
* state · …
recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[57] · oneOf[3] · $ref #/$defs/SessionGrantRequestBody
Closed returning-human, Agent runtime or fresh-device recovery issuance union. OIDC authorization codes are consumed only by account_handoff_request_body and never by this operation.
oneOf · oneOf[0] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[2] · …
recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[58] · object · $ref #/$defs/SignalSubmitOutcome
Result of transient Signal admission. accepted=true means the service placed the encrypted envelope on the short-lived rail; it creates no Event, RealmCommit, authority-stream position or durable delivery receipt.
* accepted · …
recursion truncated at depth 8; see source schema for full shape
* realm_id · …
recursion truncated at depth 8; see source schema for full shape
* envelope_digest · …
recursion truncated at depth 8; see source schema for full shape
dispatched_recipient_count · …
recursion truncated at depth 8; see source schema for full shape
server_received_at · …
recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[59] · object · $ref #/$defs/SignedSessionGrantClaims
Canonical signed claims carried by an ak.session.grant JWT. Except for the fixed kind and derived jti, the closed issuance preimage fields are copied from these claims. credential_class and holder_binding are signed and jointly determine the authorization profile; recovery_session is never refreshable or upgradable and recovery completion issues a distinct standard credential. Verifiers MUST RFC 8785-canonicalize the complete claim-derived preimage, recompute SHA-256, prepend the active sha256 suite wire code, derive ak:session_grant:<44-char-token>, and require byte equality with jti. Changing either binding therefore changes the ID.
allOf · allOf[0] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] · …
recursion truncated at depth 8; see source schema for full shape
* kind · …
recursion truncated at depth 8; see source schema for full shape
* jti · …
recursion truncated at depth 8; see source schema for full shape
* issuer_id · …
recursion truncated at depth 8; see source schema for full shape
* issuance_nonce · …
recursion truncated at depth 8; see source schema for full shape
* account_id · …
recursion truncated at depth 8; see source schema for full shape
* session_public_key · …
recursion truncated at depth 8; see source schema for full shape
* audience_id · …
recursion truncated at depth 8; see source schema for full shape
* scopes · …
recursion truncated at depth 8; see source schema for full shape
* not_before · …
recursion truncated at depth 8; see source schema for full shape
* expires_at · …
recursion truncated at depth 8; see source schema for full shape
* session_id · …
recursion truncated at depth 8; see source schema for full shape
* credential_class · …
recursion truncated at depth 8; see source schema for full shape
device_binding · …
recursion truncated at depth 8; see source schema for full shape
* holder_binding · …
recursion truncated at depth 8; see source schema for full shape
proof_kind · …
recursion truncated at depth 8; see source schema for full shape
scope_details · …
recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[60] · oneOf[2] · $ref #/$defs/CommittedEventView
Caller-scoped, non-durable read representation pairing one RealmCommit with either the exact producer-signed Event or a minimal withheld marker. It has no independent identity, signature or persistence semantics and is never reducer input.
oneOf · oneOf[0] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] · object
context · const "ak.mls_welcome_delivery_signature.v1"
enum: "ak.mls_welcome_delivery_signature.v1"
ack_token · string
Server-issued opaque acknowledgement token, REQUIRED whenever deliveries[] is non-empty. Covers both delivery kinds in this page and earlier items for the authenticated recipient endpoint. Queue deletion happens only through ak.self.device_messages.command.ack.v1 with this token, never through the after= read cursor (client-sync.md §10.1).
next_cursor · string
Read-only continuation position; advancing it MUST NOT delete queued messages.
* has_more · boolean
limited · boolean
lost · boolean
SHOULD be true only for a durably evidenced historical gap or failure since this recipient endpoint's last acknowledged position; normal expiry and capacity MUST NOT delete unacknowledged deliveries of either kind. Clients MUST re-establish MLS/key readiness when true.
anyOf · anyOf[18] · object · $ref #/$defs/DeviceMessagesSendOutcome
* delivered · object
Principal-id to device-id map for messages accepted for delivery.
* unknown_devices · object
Principal-id to device-id map for recipient targets that are not deliverable. Membership alone is the whole result: unknown, revoked, fenced or otherwise undeliverable devices are indistinguishable. A sender-side invalid expires_at never lands here; it fails the whole request.
anyOf · anyOf[19] · object · $ref #/$defs/DeviceMessagesSendRequestBody
* messages · object
Station-local did_core_id -> device_id map. The authenticated addressed Station supplies the AccountId Station component; this body carries no cross-Station route and MUST NOT use ActorId JSON as a key.
anyOf · anyOf[20] · object · $ref #/$defs/DidOperationSubmitOutcome
* status · string (enum)
enum: "accepted" "duplicate" "pending"
* did · string · $ref ./common-ids.schema.json#/$defs/did
Canonical bare DID used for registration, DID method resolution and owner-published current resolution. It contains no path, query or fragment and MUST project through the registered method adapter to exactly one did_core_id.
pattern: ^did:[a-z0-9]+:[^\s/?#]+$
* accepted_at · string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
seq · integer
New method sequence number when available.
* operation_ref · string
Exact method-native immutable operation identifier. For did:webvh this is did + "?versionId=" + the submitted entry versionId. The authenticated response acknowledges the exact complete submitted operation, including proofs; accepted/duplicate MUST match the locally frozen typed request and its method-native version and sequence. A registry MUST NOT normalize or replace accepted entry bytes. A duplicate returns the original result for the same bytes.
receipts · array<object>
items · object
anyOf · anyOf[21] · object · $ref #/$defs/DidOperationSubmitRequestBody
* did · string · $ref ./common-ids.schema.json#/$defs/did
Canonical bare DID used for registration, DID method resolution and owner-published current resolution. It contains no path, query or fragment and MUST project through the registered method adapter to exactly one did_core_id.
pattern: ^did:[a-z0-9]+:[^\s/?#]+$
* did_method · string
DID method discriminator without the did: prefix (e.g. web, webvh, key). It MUST exactly equal the method component of did; verifiers dispatch method-specific validation only after that equality check.
pattern: ^[a-z0-9]+$
seq · integer
Optional method sequence number when the DID method exposes one.
prev_event_digest · string
Optional previous operation hash / key-log head, when required by the DID method.
pattern: ^sha256:[0-9a-f]{64}$
* operation · object
Complete DID method-native operation, including every controller/update/recovery proof required by that method. This is not a generic JSON Patch. The selected adapter MUST validate the immutable native operation and its full history before any state mutation; transport authentication never substitutes for method-native control proof.
anyOf · anyOf[22] · oneOf[2] · $ref #/$defs/DirectConversationFoundingAuthorityEvidence
Closed XOR authorization evidence for one Direct Conversation founding unit, matching the two registered ak.realm.create admission variants. The human branch feeds direct_conversation_genesis; the controller_agent branch feeds direct_conversation_agent_genesis. Carrying both, neither, or mixed branch fields rejects the whole unit.
oneOf · oneOf[0] · object
* kind · const "human"
enum: "human"
* contact_round_evidence · object · $ref ./contact-operations.schema.json#/$defs/contact_round_evidence_bundle
Portable evidence for the pair's current Contact round. The verifier re-derives founder from the root Contact round, never from the current round.
allOf · allOf[0] · ?
* contact_round_id · string · $ref ./principal-operations.schema.json#/$defs/digest
pattern: ^sha256:[0-9a-f]{64}$
previous_terminal_contact_round_id · string · $ref ./principal-operations.schema.json#/$defs/digest
Absent only for a root Contact round. On recontact it is copied from every signed request fact and request acceptance receipt in this bundle and points to the immediately preceding terminal round. The bundle field is derived convenience, never independent authority.
pattern: ^sha256:[0-9a-f]{64}$
* contact_round · $ref #/$defs/contact_round · $ref #/$defs/contact_round
* request_receipts · array<$ref #/$defs/request_acceptance_receipt>
items · $ref #/$defs/request_acceptance_receipt · $ref #/$defs/request_acceptance_receipt
normal_response_receipt · $ref #/$defs/normal_response_acceptance_receipt · $ref #/$defs/normal_response_acceptance_receipt
glare_concurrency_attestations · array<$ref #/$defs/glare_concurrency_attestation>
items · $ref #/$defs/glare_concurrency_attestation · $ref #/$defs/glare_concurrency_attestation
* current_proofs · array<$ref #/$defs/contact_current_proof>
items · $ref #/$defs/contact_current_proof · $ref #/$defs/contact_current_proof
continuity_checkpoint · $ref #/$defs/bilateral_continuity_checkpoint · $ref #/$defs/bilateral_continuity_checkpoint
Latest mutually signed compacted prefix for this lineage. Its presence changes the chain terminator from the root round to covered_through_contact_round_id; it never changes the root basis or participant authority pair.
* contact_round_continuity_chains · array<$ref ./contact-operations.schema.json#/$defs/contact_round_evidence_bundle>
Ordered tombstone/recontact predecessors from the current Contact round back to the pair's unique root Contact round, each linked by previous_terminal_contact_round_id. An empty array means the current round is itself the root. A break, a cycle, multiple roots or two directional proofs yielding different roots reject the unit.
items · object · $ref ./contact-operations.schema.json#/$defs/contact_round_evidence_bundle
allOf · allOf[0] · ?
* contact_round_id · string · $ref ./principal-operations.schema.json#/$defs/digest
pattern: ^sha256:[0-9a-f]{64}$
previous_terminal_contact_round_id · string · $ref ./principal-operations.schema.json#/$defs/digest
Absent only for a root Contact round. On recontact it is copied from every signed request fact and request acceptance receipt in this bundle and points to the immediately preceding terminal round. The bundle field is derived convenience, never independent authority.
pattern: ^sha256:[0-9a-f]{64}$
* contact_round · $ref #/$defs/contact_round · $ref #/$defs/contact_round
* request_receipts · array<$ref #/$defs/request_acceptance_receipt>
items · $ref #/$defs/request_acceptance_receipt · $ref #/$defs/request_acceptance_receipt
normal_response_receipt · $ref #/$defs/normal_response_acceptance_receipt · $ref #/$defs/normal_response_acceptance_receipt
glare_concurrency_attestations · array<$ref #/$defs/glare_concurrency_attestation>
items · $ref #/$defs/glare_concurrency_attestation · $ref #/$defs/glare_concurrency_attestation
* current_proofs · array<$ref #/$defs/contact_current_proof>
items · $ref #/$defs/contact_current_proof · $ref #/$defs/contact_current_proof
continuity_checkpoint · $ref #/$defs/bilateral_continuity_checkpoint · $ref #/$defs/bilateral_continuity_checkpoint
Latest mutually signed compacted prefix for this lineage. Its presence changes the chain terminator from the root round to covered_through_contact_round_id; it never changes the root basis or participant authority pair.
oneOf · oneOf[1] · object
* kind · const "controller_agent"
enum: "controller_agent"
* agent_provision_ref · string · $ref ./principal-operations.schema.json#/$defs/event_id
Complete identity of the accepted Agent provision Event. Its digest is derived by decoding this suite-tagged full-digest EventId; no parallel agent_provision_digest is carried.
pattern: ^ak:event:[A-Za-z0-9_-]{44}$
* controller_binding_digest · string · $ref ./principal-operations.schema.json#/$defs/digest
pattern: ^sha256:[0-9a-f]{64}$
anyOf · anyOf[23] · object · $ref #/$defs/EventAdmissionSubmission
One exact producer-signed Event submitted to the current governance Station, plus the approval signatures required by a grant, Realm governance or List WIP policy for the Event action or for this registered submit operation. There are no RealmCommit, typed current result, offline-lease or proof-bundle sidecars. approval_signatures is the only sidecar and it is deliberately outside event: the Event bytes and event_id are finished before any approval is signed, so attaching them never changes the Event (zh/authz/constraint-schema.md section 9.2.5).
* event · object · $ref ./event-envelope.schema.json
Closed producer-signed Event. Shared persistent Events become final only when the current Realm governance Station issues a RealmCommit in the derived Realm, Circle, or Sidecar stream.
allOf · allOf[0] · ?
allOf · allOf[1] · ?
allOf · allOf[2] · ?
allOf · allOf[3] · ?
allOf · allOf[4] · ?
allOf · allOf[5] · $ref #/$defs/registered_admission_shape · $ref #/$defs/registered_admission_shape
allOf · allOf[6] · $ref #/$defs/registered_execution_shape · $ref #/$defs/registered_execution_shape
allOf · allOf[7] · ?
allOf · allOf[8] · ?
allOf · allOf[9] · ?
allOf · allOf[10] · ?
allOf · allOf[11] · ?
allOf · allOf[12] · ?
allOf · allOf[13] · ?
allOf · allOf[14] · ?
allOf · allOf[15] · ?
allOf · allOf[16] · ?
allOf · allOf[17] · ?
allOf · allOf[18] · ?
allOf · allOf[19] · ?
allOf · allOf[20] · ?
allOf · allOf[21] · ?
allOf · allOf[22] · ?
allOf · allOf[23] · ?
allOf · allOf[24] · ?
allOf · allOf[25] · ?
allOf · allOf[26] · ?
allOf · allOf[27] · ?
allOf · allOf[28] · ?
allOf · allOf[29] · ?
allOf · allOf[30] · ?
allOf · allOf[31] · ?
allOf · allOf[32] · ?
allOf · allOf[33] · ?
allOf · allOf[34] · ?
allOf · allOf[35] · ?
allOf · allOf[36] · ?
allOf · allOf[37] · ?
allOf · allOf[38] · ?
allOf · allOf[39] · ?
allOf · allOf[40] · ?
allOf · allOf[41] · ?
allOf · allOf[42] · ?
allOf · allOf[43] · ?
allOf · allOf[44] · ?
allOf · allOf[45] · ?
allOf · allOf[46] · ?
allOf · allOf[47] · ?
allOf · allOf[48] · ?
allOf · allOf[49] · ?
allOf · allOf[50] · ?
allOf · allOf[51] · ?
allOf · allOf[52] · ?
allOf · allOf[53] · ?
allOf · allOf[54] · ?
allOf · allOf[55] · ?
allOf · allOf[56] · ?
allOf · allOf[57] · ?
allOf · allOf[58] · ?
allOf · allOf[59] · ?
allOf · allOf[60] · ?
allOf · allOf[61] · ?
allOf · allOf[62] · ?
allOf · allOf[63] · ?
allOf · allOf[64] · ?
allOf · allOf[65] · ?
allOf · allOf[66] · ?
allOf · allOf[67] · ?
allOf · allOf[68] · ?
allOf · allOf[69] · ?
allOf · allOf[70] · ?
allOf · allOf[71] · ?
allOf · allOf[72] · ?
allOf · allOf[73] · ?
allOf · allOf[74] · ?
allOf · allOf[75] · ?
allOf · allOf[76] · ?
allOf · allOf[77] · ?
allOf · allOf[78] · ?
allOf · allOf[79] · ?
allOf · allOf[80] · ?
allOf · allOf[81] · ?
allOf · allOf[82] · ?
allOf · allOf[83] · ?
allOf · allOf[84] · ?
allOf · allOf[85] · ?
allOf · allOf[86] · ?
allOf · allOf[87] · ?
allOf · allOf[88] · ?
allOf · allOf[89] · ?
allOf · allOf[90] · ?
allOf · allOf[91] · ?
allOf · allOf[92] · ?
allOf · allOf[93] · ?
allOf · allOf[94] · ?
allOf · allOf[95] · ?
allOf · allOf[96] · ?
allOf · allOf[97] · ?
allOf · allOf[98] · ?
allOf · allOf[99] · ?
allOf · allOf[100] · ?
allOf · allOf[101] · ?
allOf · allOf[102] · ?
allOf · allOf[103] · ?
allOf · allOf[104] · ?
allOf · allOf[105] · ?
allOf · allOf[106] · ?
allOf · allOf[107] · ?
allOf · allOf[108] · ?
allOf · allOf[109] · ?
allOf · allOf[110] · ?
allOf · allOf[111] · ?
allOf · allOf[112] · ?
allOf · allOf[113] · ?
allOf · allOf[114] · ?
allOf · allOf[115] · ?
allOf · allOf[116] · ?
allOf · allOf[117] · ?
allOf · allOf[118] · ?
allOf · allOf[119] · ?
allOf · allOf[120] · ?
allOf · allOf[121] · ?
allOf · allOf[122] · ?
allOf · allOf[123] · ?
allOf · allOf[124] · ?
allOf · allOf[125] · ?
allOf · allOf[126] · ?
allOf · allOf[127] · ?
allOf · allOf[128] · ?
allOf · allOf[129] · ?
allOf · allOf[130] · ?
allOf · allOf[131] · ?
allOf · allOf[132] · ?
allOf · allOf[133] · ?
allOf · allOf[134] · ?
allOf · allOf[135] · ?
allOf · allOf[136] · ?
allOf · allOf[137] · ?
allOf · allOf[138] · ?
allOf · allOf[139] · ?
allOf · allOf[140] · ?
* event_id · string · $ref ./common-ids.schema.json#/$defs/event_id
Complete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern: ^ak:event:[A-Za-z0-9_-]{44}$
* kind · string
Standard ak.* Event kinds MUST appear in artifacts/registry/event-kind-registry.json. State convergence is defined by the registered pure reducer over kind + payload; producers do not submit typed current result writes.
pattern: ^ak\.[a-z0-9_]+(\.[a-z0-9_]+)*$
realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* scope_ref · $ref #/$defs/scope_ref · $ref #/$defs/scope_ref
Required producer-signed security scope. The closed union is ordinary existing realm, circle, or native sidecar scope plus the create-only realm_genesis exception. It enters proof.event_digest and E2EE AAD. Reducers independently derive the exact scope from schema-validated payload and accepted references; missing dependencies, nonexistent scope, realm_id mismatch, omitted sidecar_id, substituting circle for sidecar, or any unequal field is fail closed. Sidecar domain Event kinds remain Extension-owned; recognizing this native security shape does not make Kernel interpret the Sidecar reducer. Exact product targets remain inside recipient-visible ciphertext.
* actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind · const "account"
enum: "account"
* account_id · $ref #/$defs/account_id · $ref #/$defs/account_id
oneOf · oneOf[1] · object
* kind · const "service"
enum: "service"
* service_id · $ref #/$defs/did_core_id · $ref #/$defs/did_core_id
executed_by · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind · const "account"
enum: "account"
* account_id · $ref #/$defs/account_id · $ref #/$defs/account_id
oneOf · oneOf[1] · object
* kind · const "service"
enum: "service"
* service_id · $ref #/$defs/did_core_id · $ref #/$defs/did_core_id
authorization_ref · oneOf[6]
Optional. Required when executed_by is present. It identifies an accepted Grant, delegation Event, DID-document delegation, or one of the closed profile-specific authority constants. The current governance Station evaluates the reference against the target stream's committed state.
oneOf · oneOf[0] · $ref #/$defs/grant_ref · $ref #/$defs/grant_ref
oneOf · oneOf[1] · $ref #/$defs/event_ref · $ref #/$defs/event_ref
oneOf · oneOf[2] · $ref #/$defs/did_delegation_ref · $ref #/$defs/did_delegation_ref
oneOf · oneOf[3] · $ref #/$defs/direct_conversation_participant_authority_ref · $ref #/$defs/direct_conversation_participant_authority_ref
oneOf · oneOf[4] · $ref #/$defs/direct_conversation_bootstrap_authority_ref · $ref #/$defs/direct_conversation_bootstrap_authority_ref
oneOf · oneOf[5] · $ref #/$defs/membership_compensation_delegation_ref · $ref #/$defs/membership_compensation_delegation_ref
applet_id · $ref #/$defs/applet_id · $ref #/$defs/applet_id
Optional signed Applet provenance. Required by ak.profile.applet_* when the Event is introduced by an Applet, Ghost Actor, bridge, or delegated applet path. Enters canonical event bytes and therefore is covered by proof.event_digest. When present, authorization_ref MUST also be present and resolve to a real active registration/capability grant binding this applet_id, registration_epoch, action and resource per zh/extensions/applet-integration.md sections 4, 8 and 11. Service-actor self-signature proves provenance but is not an authorization substitute. Capability-gated actions require a grant covering action/resource. For subject_only operations the referenced grant binds only the exact active install and cannot replace the subject signature, FSM or independent action authority. Service self-authored Events use ActorId.service; the install grant subject MUST be the same exact ActorId.service as its producer; hosting Station and effective scope are verified separately without coercing a Service into an account variant.
external_ref · $ref #/$defs/external_ref · $ref #/$defs/external_ref
Optional signed external provenance reference for Applet / bridge-originated Events. It is covered by event_digest and MUST NOT be carried only in unsigned when used for loop prevention, audit, or external-message idempotency. Must not contain unauthorized external plaintext.
* created_at · $ref #/$defs/canonical_event_timestamp · $ref #/$defs/canonical_event_timestamp
semantic_refs · array<$ref #/$defs/semantic_ref>
Optional semantic refs with role. Omit when there are no semantic references; an explicitly empty array is not canonical. Admission selectors determine any required references. PCR policy recovery has no DID-root anchor reference; its policy/session/replacement-key authority is verified separately.
items · $ref #/$defs/semantic_ref · $ref #/$defs/semantic_ref
* payload · object
* producer_proof · $ref #/$defs/event_proof · $ref #/$defs/event_proof
The Event's sole portable producer proof. Storage receipts are separate objects and never authorize this Event. producer_proof and unsigned remain outside the canonical Event digest. Exact retries preserve the verified producer proof.
approval_signatures · array<$ref ./approval-signature.schema.json>
One ak.schema.approval_signature.v1 object per approver. An event-target signature binds approval_target.event_id equal to event.event_id. An operation-target signature is allowed only when capability-action-registry.json resolves its action to this exact carrier operation and binds request_canonical_digest to the original typed request with approval_signatures omitted. Every ingress that wraps EventAdmissionSubmission -- ordinary self submit, batch submission, control transactions, facade hand-off -- reuses this one field and MUST NOT define its own DTO. The array is omitted when no approval layer demands evidence; it MUST NOT be present and empty. The governance Station persists the evidence, the verification basis, the nonce consumption and the binding to this submission inside the same atomic acceptance transaction, and the shared Realm Event store keeps the original Event bytes unchanged.
items · object · $ref ./approval-signature.schema.json
The single approval evidence type of v1 (zh/authz/constraint-schema.md section 9.2). One approver signs one exact target: either a fully authored Event that has not been submitted yet, or the original typed RequestBody of one operation whose evidence carrier is registered in capability-action-registry.json. The object is not an Event, never enters Realm history, and MUST NOT be written into an EventEnvelope, a signed payload or an Event semantic_refs[] entry. It travels in the carrier registered for the approved action. It proves that an approver approved that target; it proves nothing about the initiator's own authority.
* input · $ref #/$defs/approval_signature_input · $ref #/$defs/approval_signature_input
* proof · $ref #/$defs/approval_signature_proof · $ref #/$defs/approval_signature_proof
anyOf · anyOf[24] · object · $ref #/$defs/EventDeliveryStatusOutcome
Complete frozen target set for one visible Event. Rows are sorted byte-wise by unique opaque target_id. Consumers derive the pending count by counting pending_route and pending_delivery rows, and derive aggregate state as pending iff that count is non-zero.
* event_id · string · $ref #/$defs/EventId
pattern: ^ak:event:[A-Za-z0-9_-]{44}$
* targets · array<$ref #/$defs/EventDeliveryTargetStatus>
items · object · $ref #/$defs/EventDeliveryTargetStatus
Authorized projection of one frozen Realm fanout target. target_id is opaque and stable. service_id is present only when the caller can currently read at least one exact joined-member ActorId that contributed the target.
* target_id · string
Service-generated opaque target identifier. It MUST NOT encode the target service DID.
pattern: ^[A-Za-z0-9][A-Za-z0-9_-]{15,127}$
* status · string (enum) · $ref #/$defs/EventDeliveryTargetState
Closed lifecycle for one frozen distinct Realm fanout target. Authority loss is terminal and a later rejoin never revives the old target.
enum: "pending_route" "pending_delivery" "delivered" "cancelled_authority_lost"
service_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
anyOf · anyOf[25] · object · $ref #/$defs/EventDeliveryStatusRequestBody
Authenticated, non-enumerating request for the durable fanout state of one caller-visible accepted Event.
* event_id · string · $ref #/$defs/EventId
pattern: ^ak:event:[A-Za-z0-9_-]{44}$
anyOf · anyOf[26] · object · $ref #/$defs/EventSubmitEnvelope
Closed producer-signed Event. Shared persistent Events become final only when the current Realm governance Station issues a RealmCommit in the derived Realm, Circle, or Sidecar stream.
allOf · allOf[0] · ?
allOf · allOf[1] · ?
allOf · allOf[2] · ?
allOf · allOf[3] · ?
allOf · allOf[4] · ?
allOf · allOf[5] · $ref #/$defs/registered_admission_shape · $ref #/$defs/registered_admission_shape
allOf · allOf[6] · $ref #/$defs/registered_execution_shape · $ref #/$defs/registered_execution_shape
allOf · allOf[7] · ?
allOf · allOf[8] · ?
allOf · allOf[9] · ?
allOf · allOf[10] · ?
allOf · allOf[11] · ?
allOf · allOf[12] · ?
allOf · allOf[13] · ?
allOf · allOf[14] · ?
allOf · allOf[15] · ?
allOf · allOf[16] · ?
allOf · allOf[17] · ?
allOf · allOf[18] · ?
allOf · allOf[19] · ?
allOf · allOf[20] · ?
allOf · allOf[21] · ?
allOf · allOf[22] · ?
allOf · allOf[23] · ?
allOf · allOf[24] · ?
allOf · allOf[25] · ?
allOf · allOf[26] · ?
allOf · allOf[27] · ?
allOf · allOf[28] · ?
allOf · allOf[29] · ?
allOf · allOf[30] · ?
allOf · allOf[31] · ?
allOf · allOf[32] · ?
allOf · allOf[33] · ?
allOf · allOf[34] · ?
allOf · allOf[35] · ?
allOf · allOf[36] · ?
allOf · allOf[37] · ?
allOf · allOf[38] · ?
allOf · allOf[39] · ?
allOf · allOf[40] · ?
allOf · allOf[41] · ?
allOf · allOf[42] · ?
allOf · allOf[43] · ?
allOf · allOf[44] · ?
allOf · allOf[45] · ?
allOf · allOf[46] · ?
allOf · allOf[47] · ?
allOf · allOf[48] · ?
allOf · allOf[49] · ?
allOf · allOf[50] · ?
allOf · allOf[51] · ?
allOf · allOf[52] · ?
allOf · allOf[53] · ?
allOf · allOf[54] · ?
allOf · allOf[55] · ?
allOf · allOf[56] · ?
allOf · allOf[57] · ?
allOf · allOf[58] · ?
allOf · allOf[59] · ?
allOf · allOf[60] · ?
allOf · allOf[61] · ?
allOf · allOf[62] · ?
allOf · allOf[63] · ?
allOf · allOf[64] · ?
allOf · allOf[65] · ?
allOf · allOf[66] · ?
allOf · allOf[67] · ?
allOf · allOf[68] · ?
allOf · allOf[69] · ?
allOf · allOf[70] · ?
allOf · allOf[71] · ?
allOf · allOf[72] · ?
allOf · allOf[73] · ?
allOf · allOf[74] · ?
allOf · allOf[75] · ?
allOf · allOf[76] · ?
allOf · allOf[77] · ?
allOf · allOf[78] · ?
allOf · allOf[79] · ?
allOf · allOf[80] · ?
allOf · allOf[81] · ?
allOf · allOf[82] · ?
allOf · allOf[83] · ?
allOf · allOf[84] · ?
allOf · allOf[85] · ?
allOf · allOf[86] · ?
allOf · allOf[87] · ?
allOf · allOf[88] · ?
allOf · allOf[89] · ?
allOf · allOf[90] · ?
allOf · allOf[91] · ?
allOf · allOf[92] · ?
allOf · allOf[93] · ?
allOf · allOf[94] · ?
allOf · allOf[95] · ?
allOf · allOf[96] · ?
allOf · allOf[97] · ?
allOf · allOf[98] · ?
allOf · allOf[99] · ?
allOf · allOf[100] · ?
allOf · allOf[101] · ?
allOf · allOf[102] · ?
allOf · allOf[103] · ?
allOf · allOf[104] · ?
allOf · allOf[105] · ?
allOf · allOf[106] · ?
allOf · allOf[107] · ?
allOf · allOf[108] · ?
allOf · allOf[109] · ?
allOf · allOf[110] · ?
allOf · allOf[111] · ?
allOf · allOf[112] · ?
allOf · allOf[113] · ?
allOf · allOf[114] · ?
allOf · allOf[115] · ?
allOf · allOf[116] · ?
allOf · allOf[117] · ?
allOf · allOf[118] · ?
allOf · allOf[119] · ?
allOf · allOf[120] · ?
allOf · allOf[121] · ?
allOf · allOf[122] · ?
allOf · allOf[123] · ?
allOf · allOf[124] · ?
allOf · allOf[125] · ?
allOf · allOf[126] · ?
allOf · allOf[127] · ?
allOf · allOf[128] · ?
allOf · allOf[129] · ?
allOf · allOf[130] · ?
allOf · allOf[131] · ?
allOf · allOf[132] · ?
allOf · allOf[133] · ?
allOf · allOf[134] · ?
allOf · allOf[135] · ?
allOf · allOf[136] · ?
allOf · allOf[137] · ?
allOf · allOf[138] · ?
allOf · allOf[139] · ?
allOf · allOf[140] · ?
* event_id · string · $ref ./common-ids.schema.json#/$defs/event_id
Complete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern: ^ak:event:[A-Za-z0-9_-]{44}$
* kind · string
Standard ak.* Event kinds MUST appear in artifacts/registry/event-kind-registry.json. State convergence is defined by the registered pure reducer over kind + payload; producers do not submit typed current result writes.
pattern: ^ak\.[a-z0-9_]+(\.[a-z0-9_]+)*$
realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* scope_ref · $ref #/$defs/scope_ref · $ref #/$defs/scope_ref
Required producer-signed security scope. The closed union is ordinary existing realm, circle, or native sidecar scope plus the create-only realm_genesis exception. It enters proof.event_digest and E2EE AAD. Reducers independently derive the exact scope from schema-validated payload and accepted references; missing dependencies, nonexistent scope, realm_id mismatch, omitted sidecar_id, substituting circle for sidecar, or any unequal field is fail closed. Sidecar domain Event kinds remain Extension-owned; recognizing this native security shape does not make Kernel interpret the Sidecar reducer. Exact product targets remain inside recipient-visible ciphertext.
* actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind · const "account"
enum: "account"
* account_id · $ref #/$defs/account_id · $ref #/$defs/account_id
oneOf · oneOf[1] · object
* kind · const "service"
enum: "service"
* service_id · $ref #/$defs/did_core_id · $ref #/$defs/did_core_id
executed_by · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind · const "account"
enum: "account"
* account_id · $ref #/$defs/account_id · $ref #/$defs/account_id
oneOf · oneOf[1] · object
* kind · const "service"
enum: "service"
* service_id · $ref #/$defs/did_core_id · $ref #/$defs/did_core_id
authorization_ref · oneOf[6]
Optional. Required when executed_by is present. It identifies an accepted Grant, delegation Event, DID-document delegation, or one of the closed profile-specific authority constants. The current governance Station evaluates the reference against the target stream's committed state.
oneOf · oneOf[0] · $ref #/$defs/grant_ref · $ref #/$defs/grant_ref
oneOf · oneOf[1] · $ref #/$defs/event_ref · $ref #/$defs/event_ref
oneOf · oneOf[2] · $ref #/$defs/did_delegation_ref · $ref #/$defs/did_delegation_ref
oneOf · oneOf[3] · $ref #/$defs/direct_conversation_participant_authority_ref · $ref #/$defs/direct_conversation_participant_authority_ref
oneOf · oneOf[4] · $ref #/$defs/direct_conversation_bootstrap_authority_ref · $ref #/$defs/direct_conversation_bootstrap_authority_ref
oneOf · oneOf[5] · $ref #/$defs/membership_compensation_delegation_ref · $ref #/$defs/membership_compensation_delegation_ref
applet_id · $ref #/$defs/applet_id · $ref #/$defs/applet_id
Optional signed Applet provenance. Required by ak.profile.applet_* when the Event is introduced by an Applet, Ghost Actor, bridge, or delegated applet path. Enters canonical event bytes and therefore is covered by proof.event_digest. When present, authorization_ref MUST also be present and resolve to a real active registration/capability grant binding this applet_id, registration_epoch, action and resource per zh/extensions/applet-integration.md sections 4, 8 and 11. Service-actor self-signature proves provenance but is not an authorization substitute. Capability-gated actions require a grant covering action/resource. For subject_only operations the referenced grant binds only the exact active install and cannot replace the subject signature, FSM or independent action authority. Service self-authored Events use ActorId.service; the install grant subject MUST be the same exact ActorId.service as its producer; hosting Station and effective scope are verified separately without coercing a Service into an account variant.
external_ref · $ref #/$defs/external_ref · $ref #/$defs/external_ref
Optional signed external provenance reference for Applet / bridge-originated Events. It is covered by event_digest and MUST NOT be carried only in unsigned when used for loop prevention, audit, or external-message idempotency. Must not contain unauthorized external plaintext.
* created_at · $ref #/$defs/canonical_event_timestamp · $ref #/$defs/canonical_event_timestamp
semantic_refs · array<$ref #/$defs/semantic_ref>
Optional semantic refs with role. Omit when there are no semantic references; an explicitly empty array is not canonical. Admission selectors determine any required references. PCR policy recovery has no DID-root anchor reference; its policy/session/replacement-key authority is verified separately.
items · $ref #/$defs/semantic_ref · $ref #/$defs/semantic_ref
* payload · object
* producer_proof · $ref #/$defs/event_proof · $ref #/$defs/event_proof
The Event's sole portable producer proof. Storage receipts are separate objects and never authorize this Event. producer_proof and unsigned remain outside the canonical Event digest. Exact retries preserve the verified producer proof.
anyOf · anyOf[27] · object · $ref #/$defs/EventsSubmitBatchRequestBody
Legacy-named typed array retained only as the nested prepared_event_unit request in security-transaction.schema.json. It is not an ak.self.events.command.submit.v1 request: that operation accepts only authority-commit-operations.schema.json#/$defs/self_submit_request, including its closed ordinary_realm_bootstrap branch. The parent security transaction fixes the recovery unit type, slot count, order and authorization; this array alone grants no generic Event batch admission.
* events · array<$ref #/$defs/EventAdmissionSubmission>
items · object · $ref #/$defs/EventAdmissionSubmission
One exact producer-signed Event submitted to the current governance Station, plus the approval signatures required by a grant, Realm governance or List WIP policy for the Event action or for this registered submit operation. There are no RealmCommit, typed current result, offline-lease or proof-bundle sidecars. approval_signatures is the only sidecar and it is deliberately outside event: the Event bytes and event_id are finished before any approval is signed, so attaching them never changes the Event (zh/authz/constraint-schema.md section 9.2.5).
* event · object · $ref ./event-envelope.schema.json
Closed producer-signed Event. Shared persistent Events become final only when the current Realm governance Station issues a RealmCommit in the derived Realm, Circle, or Sidecar stream.
allOf · allOf[0] · ?
allOf · allOf[1] · ?
allOf · allOf[2] · ?
allOf · allOf[3] · ?
allOf · allOf[4] · ?
allOf · allOf[5] · $ref #/$defs/registered_admission_shape · $ref #/$defs/registered_admission_shape
allOf · allOf[6] · $ref #/$defs/registered_execution_shape · $ref #/$defs/registered_execution_shape
allOf · allOf[7] · ?
allOf · allOf[8] · ?
allOf · allOf[9] · ?
allOf · allOf[10] · ?
allOf · allOf[11] · ?
allOf · allOf[12] · ?
allOf · allOf[13] · ?
allOf · allOf[14] · ?
allOf · allOf[15] · ?
allOf · allOf[16] · ?
allOf · allOf[17] · ?
allOf · allOf[18] · ?
allOf · allOf[19] · ?
allOf · allOf[20] · ?
allOf · allOf[21] · ?
allOf · allOf[22] · ?
allOf · allOf[23] · ?
allOf · allOf[24] · ?
allOf · allOf[25] · ?
allOf · allOf[26] · ?
allOf · allOf[27] · ?
allOf · allOf[28] · ?
allOf · allOf[29] · ?
allOf · allOf[30] · ?
allOf · allOf[31] · ?
allOf · allOf[32] · ?
allOf · allOf[33] · ?
allOf · allOf[34] · ?
allOf · allOf[35] · ?
allOf · allOf[36] · ?
allOf · allOf[37] · ?
allOf · allOf[38] · ?
allOf · allOf[39] · ?
allOf · allOf[40] · ?
allOf · allOf[41] · ?
allOf · allOf[42] · ?
allOf · allOf[43] · ?
allOf · allOf[44] · ?
allOf · allOf[45] · ?
allOf · allOf[46] · ?
allOf · allOf[47] · ?
allOf · allOf[48] · ?
allOf · allOf[49] · ?
allOf · allOf[50] · ?
allOf · allOf[51] · ?
allOf · allOf[52] · ?
allOf · allOf[53] · ?
allOf · allOf[54] · ?
allOf · allOf[55] · ?
allOf · allOf[56] · ?
allOf · allOf[57] · ?
allOf · allOf[58] · ?
allOf · allOf[59] · ?
allOf · allOf[60] · ?
allOf · allOf[61] · ?
allOf · allOf[62] · ?
allOf · allOf[63] · ?
allOf · allOf[64] · ?
allOf · allOf[65] · ?
allOf · allOf[66] · ?
allOf · allOf[67] · ?
allOf · allOf[68] · ?
allOf · allOf[69] · ?
allOf · allOf[70] · ?
allOf · allOf[71] · ?
allOf · allOf[72] · ?
allOf · allOf[73] · ?
allOf · allOf[74] · ?
allOf · allOf[75] · ?
allOf · allOf[76] · ?
allOf · allOf[77] · ?
allOf · allOf[78] · ?
allOf · allOf[79] · ?
allOf · allOf[80] · ?
allOf · allOf[81] · ?
allOf · allOf[82] · ?
allOf · allOf[83] · ?
allOf · allOf[84] · ?
allOf · allOf[85] · ?
allOf · allOf[86] · ?
allOf · allOf[87] · ?
allOf · allOf[88] · ?
allOf · allOf[89] · ?
allOf · allOf[90] · ?
allOf · allOf[91] · ?
allOf · allOf[92] · ?
allOf · allOf[93] · ?
allOf · allOf[94] · ?
allOf · allOf[95] · ?
allOf · allOf[96] · ?
allOf · allOf[97] · ?
allOf · allOf[98] · ?
allOf · allOf[99] · ?
allOf · allOf[100] · ?
allOf · allOf[101] · ?
allOf · allOf[102] · ?
allOf · allOf[103] · ?
allOf · allOf[104] · ?
allOf · allOf[105] · ?
allOf · allOf[106] · ?
allOf · allOf[107] · ?
allOf · allOf[108] · ?
allOf · allOf[109] · ?
allOf · allOf[110] · ?
allOf · allOf[111] · ?
allOf · allOf[112] · ?
allOf · allOf[113] · ?
allOf · allOf[114] · ?
allOf · allOf[115] · ?
allOf · allOf[116] · ?
allOf · allOf[117] · ?
allOf · allOf[118] · ?
allOf · allOf[119] · ?
allOf · allOf[120] · ?
allOf · allOf[121] · ?
allOf · allOf[122] · ?
allOf · allOf[123] · ?
allOf · allOf[124] · ?
allOf · allOf[125] · ?
allOf · allOf[126] · ?
allOf · allOf[127] · ?
allOf · allOf[128] · ?
allOf · allOf[129] · ?
allOf · allOf[130] · ?
allOf · allOf[131] · ?
allOf · allOf[132] · ?
allOf · allOf[133] · ?
allOf · allOf[134] · ?
allOf · allOf[135] · ?
allOf · allOf[136] · ?
allOf · allOf[137] · ?
allOf · allOf[138] · ?
allOf · allOf[139] · ?
allOf · allOf[140] · ?
* event_id · string · $ref ./common-ids.schema.json#/$defs/event_id
Complete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern: ^ak:event:[A-Za-z0-9_-]{44}$
* kind · string
Standard ak.* Event kinds MUST appear in artifacts/registry/event-kind-registry.json. State convergence is defined by the registered pure reducer over kind + payload; producers do not submit typed current result writes.
pattern: ^ak\.[a-z0-9_]+(\.[a-z0-9_]+)*$
realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* scope_ref · $ref #/$defs/scope_ref · $ref #/$defs/scope_ref
Required producer-signed security scope. The closed union is ordinary existing realm, circle, or native sidecar scope plus the create-only realm_genesis exception. It enters proof.event_digest and E2EE AAD. Reducers independently derive the exact scope from schema-validated payload and accepted references; missing dependencies, nonexistent scope, realm_id mismatch, omitted sidecar_id, substituting circle for sidecar, or any unequal field is fail closed. Sidecar domain Event kinds remain Extension-owned; recognizing this native security shape does not make Kernel interpret the Sidecar reducer. Exact product targets remain inside recipient-visible ciphertext.
* actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind · const "account"
enum: "account"
* account_id · $ref #/$defs/account_id · $ref #/$defs/account_id
oneOf · oneOf[1] · object
* kind · const "service"
enum: "service"
* service_id · $ref #/$defs/did_core_id · $ref #/$defs/did_core_id
executed_by · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind · const "account"
enum: "account"
* account_id · $ref #/$defs/account_id · $ref #/$defs/account_id
oneOf · oneOf[1] · object
* kind · const "service"
enum: "service"
* service_id · $ref #/$defs/did_core_id · $ref #/$defs/did_core_id
authorization_ref · oneOf[6]
Optional. Required when executed_by is present. It identifies an accepted Grant, delegation Event, DID-document delegation, or one of the closed profile-specific authority constants. The current governance Station evaluates the reference against the target stream's committed state.
oneOf · oneOf[0] · $ref #/$defs/grant_ref · $ref #/$defs/grant_ref
oneOf · oneOf[1] · $ref #/$defs/event_ref · $ref #/$defs/event_ref
oneOf · oneOf[2] · $ref #/$defs/did_delegation_ref · $ref #/$defs/did_delegation_ref
oneOf · oneOf[3] · $ref #/$defs/direct_conversation_participant_authority_ref · $ref #/$defs/direct_conversation_participant_authority_ref
oneOf · oneOf[4] · $ref #/$defs/direct_conversation_bootstrap_authority_ref · $ref #/$defs/direct_conversation_bootstrap_authority_ref
oneOf · oneOf[5] · $ref #/$defs/membership_compensation_delegation_ref · $ref #/$defs/membership_compensation_delegation_ref
applet_id · $ref #/$defs/applet_id · $ref #/$defs/applet_id
Optional signed Applet provenance. Required by ak.profile.applet_* when the Event is introduced by an Applet, Ghost Actor, bridge, or delegated applet path. Enters canonical event bytes and therefore is covered by proof.event_digest. When present, authorization_ref MUST also be present and resolve to a real active registration/capability grant binding this applet_id, registration_epoch, action and resource per zh/extensions/applet-integration.md sections 4, 8 and 11. Service-actor self-signature proves provenance but is not an authorization substitute. Capability-gated actions require a grant covering action/resource. For subject_only operations the referenced grant binds only the exact active install and cannot replace the subject signature, FSM or independent action authority. Service self-authored Events use ActorId.service; the install grant subject MUST be the same exact ActorId.service as its producer; hosting Station and effective scope are verified separately without coercing a Service into an account variant.
external_ref · $ref #/$defs/external_ref · $ref #/$defs/external_ref
Optional signed external provenance reference for Applet / bridge-originated Events. It is covered by event_digest and MUST NOT be carried only in unsigned when used for loop prevention, audit, or external-message idempotency. Must not contain unauthorized external plaintext.
* created_at · $ref #/$defs/canonical_event_timestamp · $ref #/$defs/canonical_event_timestamp
semantic_refs · array<$ref #/$defs/semantic_ref>
Optional semantic refs with role. Omit when there are no semantic references; an explicitly empty array is not canonical. Admission selectors determine any required references. PCR policy recovery has no DID-root anchor reference; its policy/session/replacement-key authority is verified separately.
items · $ref #/$defs/semantic_ref · $ref #/$defs/semantic_ref
* payload · object
* producer_proof · $ref #/$defs/event_proof · $ref #/$defs/event_proof
The Event's sole portable producer proof. Storage receipts are separate objects and never authorize this Event. producer_proof and unsigned remain outside the canonical Event digest. Exact retries preserve the verified producer proof.
approval_signatures · array<$ref ./approval-signature.schema.json>
One ak.schema.approval_signature.v1 object per approver. An event-target signature binds approval_target.event_id equal to event.event_id. An operation-target signature is allowed only when capability-action-registry.json resolves its action to this exact carrier operation and binds request_canonical_digest to the original typed request with approval_signatures omitted. Every ingress that wraps EventAdmissionSubmission -- ordinary self submit, batch submission, control transactions, facade hand-off -- reuses this one field and MUST NOT define its own DTO. The array is omitted when no approval layer demands evidence; it MUST NOT be present and empty. The governance Station persists the evidence, the verification basis, the nonce consumption and the binding to this submission inside the same atomic acceptance transaction, and the shared Realm Event store keeps the original Event bytes unchanged.
items · object · $ref ./approval-signature.schema.json
The single approval evidence type of v1 (zh/authz/constraint-schema.md section 9.2). One approver signs one exact target: either a fully authored Event that has not been submitted yet, or the original typed RequestBody of one operation whose evidence carrier is registered in capability-action-registry.json. The object is not an Event, never enters Realm history, and MUST NOT be written into an EventEnvelope, a signed payload or an Event semantic_refs[] entry. It travels in the carrier registered for the approved action. It proves that an approver approved that target; it proves nothing about the initiator's own authority.
* input · $ref #/$defs/approval_signature_input · $ref #/$defs/approval_signature_input
* proof · $ref #/$defs/approval_signature_proof · $ref #/$defs/approval_signature_proof
anyOf · anyOf[28] · object · $ref #/$defs/GrantList
Atomic subject-visible snapshot of active effective grants. Each row carries its own exact current-result revision; state_digest authenticates the list as a whole and is never a per-grant CAS operand.
* grants · array<$ref #/$defs/EffectiveCapabilityGrantRow>
items · object · $ref #/$defs/EffectiveCapabilityGrantRow
One active effective capability grant and the exact revision of that same capability_grant current result, read atomically by the governing Station. This revision is the only valid authoring basis for a subject-signed ak.capability.relinquish Event; state_digest, evaluated_at, Event ids and locally folded history MUST NOT substitute for it.
* grant · object · $ref ./capability-grant.schema.json
allOf · allOf[0] · ?
allOf · allOf[1] · ?
* id · string
pattern: ^ak:grant:[A-Za-z0-9_-]{44}$
* schema · const "ak.schema.capability.v1"
enum: "ak.schema.capability.v1"
realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* issuer_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind · const "account"
enum: "account"
* account_id · $ref #/$defs/account_id · $ref #/$defs/account_id
oneOf · oneOf[1] · object
* kind · const "service"
enum: "service"
* service_id · $ref #/$defs/did_core_id · $ref #/$defs/did_core_id
* subject · oneOf[2]
oneOf · oneOf[0] · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind · const "account"
enum: "account"
* account_id · $ref #/$defs/account_id · $ref #/$defs/account_id
oneOf · oneOf[1] · object
* kind · const "service"
enum: "service"
* service_id · $ref #/$defs/did_core_id · $ref #/$defs/did_core_id
oneOf · oneOf[1] · object
* kind · const "condition"
enum: "condition"
* required_claims · array<object> · $ref ./grant-constraint.schema.json#/properties/required_claims
Conditional claim requirements. resource-selector-grammar.md §3.3 caps this array at 32 entries as a normative DoS guard; the schema enforces maxItems:32 so condition-selector grants cannot smuggle in unbounded claim objects.
items · object
anyOf · anyOf[0] · …
recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[1] · …
recursion truncated at depth 8; see source schema for full shape
* claim_kind · …
recursion truncated at depth 8; see source schema for full shape
issuer_id · …
recursion truncated at depth 8; see source schema for full shape
trusted_issuer_ids · …
recursion truncated at depth 8; see source schema for full shape
subject_matches_actor · …
recursion truncated at depth 8; see source schema for full shape
value_constraints · …
recursion truncated at depth 8; see source schema for full shape
organization_id · …
recursion truncated at depth 8; see source schema for full shape
status · …
recursion truncated at depth 8; see source schema for full shape
roles · …
recursion truncated at depth 8; see source schema for full shape
* actions · array<string>
items · string
Canonical action vocabulary. MUST be of the form ak.<segment>.<segment>... matching capabilities.md §5. Bare names without the ak. prefix are not permitted; consult capabilities.md before introducing new action names. Wildcards within a segment are not permitted in this schema; the resource selector controls scope, not action expansion.
pattern: ^ak\.[a-z0-9_]+(\.[a-z0-9_]+)*$
* resources · array<$ref ./resource-selector.schema.json>
items · object · $ref ./resource-selector.schema.json
allOf · allOf[0] · ?
allOf · allOf[1] · ?
allOf · allOf[2] · ?
allOf · allOf[3] · ?
* kind · string (enum)
enum: "realm" "space" "circle" "strand" "message" "morph" "object" "relation" "view" "event" "actor" "schema" "policy" "invite" "notification" "read_cursor" "blob" "*"
realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
space_id · string
pattern: ^ak:space:[A-Za-z0-9_-]{44}$
circle_id · string · $ref ./common-ids.schema.json#/$defs/circle_id
pattern: ^ak:circle:[A-Za-z0-9_-]{44}$
object_kind · string
object_ref · string
Canonical object reference. Acceptable typed-id kinds match the v1 resource selector kind enum (see resource-selector-grammar.md §3.1). Notably MUST NOT include 'actor_profile' (use the 'actor' selector with did pattern), nor non-canonical 'board' / 'list' / 'card' / 'subject' / 'room' kinds — board / list / swimlane / calendar bucket are Space objects and MUST use the 'space' kind together with the 'allowed_space_kinds' constraint to restrict which Space kinds the grant covers.
pattern: ^(?:ak:realm:[A-Za-z0-9_-]{44}|ak:(space|circle|strand|message|morph|relation|view|event|invite):[A-Za-z0-9_-]{44}|ak:(policy|blob):[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12})$
strand_id · string
pattern: ^ak:strand:[A-Za-z0-9_-]{44}$
message_id · string
pattern: ^ak:message:[A-Za-z0-9_-]{44}$
morph_id · string
pattern: ^ak:morph:[A-Za-z0-9_-]{44}$
morph_kind · string
relation_kind · string
relation_id · string
pattern: ^ak:relation:[A-Za-z0-9_-]{44}$
view_id · string
pattern: ^ak:view:[A-Za-z0-9_-]{44}$
event_id · string
pattern: ^ak:event:[A-Za-z0-9_-]{44}$
actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind · …
recursion truncated at depth 8; see source schema for full shape
* account_id · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* kind · …
recursion truncated at depth 8; see source schema for full shape
* service_id · …
recursion truncated at depth 8; see source schema for full shape
schema_ref · string
policy_id · string
pattern: ^ak:policy:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$
invite_id · string
pattern: ^ak:invite:[A-Za-z0-9_-]{44}$
blob_ref · string
pattern: ^ak:blob:(?:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}|(?:sha256|blake3):[0-9a-f]{64})$
match_scope · string (enum)
Authorization selector breadth. exact matches only the named resource; realm_wide is valid only for the registered resource kinds with an explicit realm_id. Neither current navigation ancestry nor creation ancestry expands authorization. Hierarchy traversal belongs to queries, not grant matching. The normative algorithm is zh/authz/resource-selector-grammar.md section 6.
enum: "exact" "realm_wide"
constraints · array<$ref ./grant-constraint.schema.json>
Constraints applied to this grant. Re-grant control MUST be expressed via constraint_kind='authority_control' and max_authority_depth (see capabilities.md §10). A top-level 'delegable' field is forbidden and MUST be rejected as schema_violation. With no authority_control constraint the grant cannot be re-granted (equivalent to max_authority_depth=0).
items · object · $ref ./grant-constraint.schema.json
allOf · allOf[0] · ?
allOf · allOf[1] · ?
allOf · allOf[2] · ?
allOf · allOf[3] · ?
allOf · allOf[4] · ?
allOf · allOf[5] · ?
allOf · allOf[6] · ?
allOf · allOf[7] · ?
allOf · allOf[8] · ?
allOf · allOf[9] · ?
allOf · allOf[10] · ?
allOf · allOf[11] · ?
allOf · allOf[12] · ?
allOf · allOf[13] · ?
allOf · allOf[14] · ?
constraint_id · string
Optional stable identifier of this constraint within the grant; used for diagnostics and overrides.
pattern: ^(?!ak:)
* constraint_kind · string (enum)
Constraint family discriminator. v1 collapses what were 15 types into 8 by absorbing narrowly-scoped types into their conceptual parent: edit_window → temporal; container_move → scope_limitation; rate_limiting + resource_limit → quota; approval_workflow + accountability + device_session → claim_based (with constraint_subkind); encryption_requirement + visibility_control → confidentiality (with constraint_subkind). Use the optional 'constraint_subkind' field to indicate the original specialization where evaluation logic differs.
enum: "temporal" "field_access" "kind_restriction" "scope_limitation" "authority_control" "quota" "claim_based" "confidentiality"
* effect · string (enum)
enum: "allow" "deny" "quarantine" "require_review"
evaluation_class · string (enum)
Cacheability/dependency hint for the authorization evaluator. stateless = pure function of (constraint, op, now); grant_local = depends on the grant object only; realm_state = depends on the exact Realm authority revision (membership, policy_version, etc.); external = depends on data outside that authority state (claim revocation status, rate-limit counts, async approval). Each constraint_kind has a canonical evaluation_class declared in constraint-schema.md §2.3; implementations MAY tighten (e.g. grant_local → stateless) but MUST NOT loosen (e.g. external as stateless). Auth evaluators SHOULD use this hint to gate fast-path caching.
enum: "stateless" "grant_local" "realm_state" "external"
constraint_subkind · string (enum)
Optional discriminator within a constraint_kind. Standard values: claim_based.{claim,approval,accountability}; quota.{rate,resource}; confidentiality.{encryption,visibility}; temporal.{window,edit_window,redact_window,session}; authority_control.{applet_authority}. Per constraint-schema.md §2.2, device/session binding is NOT an independent constraint_subkind: it is the claim_based constraint_subkind=claim sub-case expressed via an accepted PCR device issuer. Implementations MAY require constraint_subkind for these families and fail closed on unknown values.
enum: "claim" "approval" "accountability" "rate" "resource" "encryption" "visibility" "window" "edit_window" "redact_window" "session" "applet_authority"
applies_to_actions · array<string>
Optional restriction of a temporal constraint to specific capability actions (e.g. ['ak.message.revise.own', 'ak.message.redact.own']). Action mismatch is neutral in the effect fold: satisfied for effect=allow and not matched for deny/quarantine/require_review.
items · string
pattern: ^ak\.[a-z0-9_]+(\.[a-z0-9_]+)*$
not_before · $ref #/$defs/timestamp · $ref #/$defs/timestamp
expires_at · $ref #/$defs/timestamp · $ref #/$defs/timestamp
recurrence · object
Recurrence rule for temporal constraints. Used by constraint-schema.md §3.1.
frequency · string (enum)
enum: "daily" "weekly" "monthly" "custom"
days · array<string (enum)>
items · …
recursion truncated at depth 8; see source schema for full shape
window_start · string
pattern: ^([01][0-9]|2[0-3]):[0-5][0-9](:[0-5][0-9])?$
window_end · string
pattern: ^([01][0-9]|2[0-3]):[0-5][0-9](:[0-5][0-9])?$
timezone · string
max_duration · string
ISO 8601 duration.
pattern: ^P(?:[0-9]+Y)?(?:[0-9]+M)?(?:[0-9]+W)?(?:[0-9]+D)?(?:T(?:[0-9]+H)?(?:[0-9]+M)?(?:[0-9]+S)?)?$
max_session_duration · string
pattern: ^P(?:[0-9]+Y)?(?:[0-9]+M)?(?:[0-9]+W)?(?:[0-9]+D)?(?:T(?:[0-9]+H)?(?:[0-9]+M)?(?:[0-9]+S)?)?$
inactivity_timeout · string
pattern: ^P(?:[0-9]+Y)?(?:[0-9]+M)?(?:[0-9]+W)?(?:[0-9]+D)?(?:T(?:[0-9]+H)?(?:[0-9]+M)?(?:[0-9]+S)?)?$
expires_after · string
ISO 8601 duration; used by approval_workflow constraint instead of expires_after_ms.
pattern: ^P(?:[0-9]+Y)?(?:[0-9]+M)?(?:[0-9]+W)?(?:[0-9]+D)?(?:T(?:[0-9]+H)?(?:[0-9]+M)?(?:[0-9]+S)?)?$
message_edit_window · string
pattern: ^P(?:[0-9]+Y)?(?:[0-9]+M)?(?:[0-9]+W)?(?:[0-9]+D)?(?:T(?:[0-9]+H)?(?:[0-9]+M)?(?:[0-9]+S)?)?$
message_redact_window · string
pattern: ^P(?:[0-9]+Y)?(?:[0-9]+M)?(?:[0-9]+W)?(?:[0-9]+D)?(?:T(?:[0-9]+H)?(?:[0-9]+M)?(?:[0-9]+S)?)?$
redact_after_window_allowed · boolean
condition · object
Conditional predicate for field_access and similar constraints. The `kind` value is a registered named condition from constraint-schema.md §4.1; unknown kinds MUST fail closed. Implementations MUST NOT introduce ad hoc string DSL predicates.
* kind · string (enum)
enum: "object_is_owned_by_actor" "actor_is_assignee" "actor_is_responsible" "actor_is_guardian" "actor_is_controller" "object_in_actor_container" "object_is_unencrypted" "object_is_encrypted" "always" "never"
allowed_write_fields · array<string>
items · string
denied_write_fields · array<string>
items · string
allowed_read_fields · array<string>
items · string
denied_read_fields · array<string>
items · string
sensitive_fields · array<string>
items · string
sensitive_handling · string (enum)
enum: "redact" "hash" "omit"
allowed_object_kinds · array<string>
items · string
denied_object_kinds · array<string>
items · string
allowed_morph_kinds · array<string>
items · string
denied_morph_kinds · array<string>
items · string
allowed_space_kinds · array<string>
Allowed Space kinds (e.g. 'board', 'list', or profile-registered kinds like 'swimlane', 'calendar_bucket'). Reducer/profile MUST validate kind value.
items · string
denied_space_kinds · array<string>
items · string
allowed_facets · array<string (enum)>
items · string (enum)
enum: "container" "replyable" "schedulable" "assignable" "stateful" "rankable" "reviewable" "notifiable" "documentable" "renderable"
denied_facets · array<string (enum)>
items · string (enum)
enum: "container" "replyable" "schedulable" "assignable" "stateful" "rankable" "reviewable" "notifiable" "documentable" "renderable"
allowed_view_ids · array<string>
items · string
pattern: ^ak:view:[A-Za-z0-9_-]{44}$
allowed_strand_ids · array<string>
items · string
pattern: ^ak:strand:[A-Za-z0-9_-]{44}$
denied_strand_ids · array<string>
items · string
pattern: ^ak:strand:[A-Za-z0-9_-]{44}$
allowed_space_ids · array<string>
items · string
pattern: ^ak:space:[A-Za-z0-9_-]{44}$
denied_space_ids · array<string>
items · string
pattern: ^ak:space:[A-Za-z0-9_-]{44}$
allowed_circle_ids · array<$ref ./common-ids.schema.json#/$defs/circle_id>
Limits Circle-scoped capability actions to the listed Circle ids. Used by ak.circle.manage / ak.circle.member.manage style grants; unconstrained Realm-wide Circle management grants are not a normal permission shape.
items · string · $ref ./common-ids.schema.json#/$defs/circle_id
pattern: ^ak:circle:[A-Za-z0-9_-]{44}$
allowed_session_ids · array<string>
Limits applet interop-session operations to the listed applet-defined session correlation ids.
items · string
pattern: ^(?!ak:)
allowed_view_kinds · array<string>
items · string
allowed_view_renderers · array<string>
items · string
denied_view_kinds · array<string>
items · string
denied_view_renderers · array<string>
items · string
allowed_relation_kinds · array<string>
items · string
allowed_from_container_refs · array<string>
items · string
pattern: ^ak:(space|strand|morph):[A-Za-z0-9_-]{44}$
allowed_to_container_refs · array<string>
items · string
pattern: ^ak:(space|strand|morph):[A-Za-z0-9_-]{44}$
wip_limit_override · boolean
example: false
allowed_tracks · array<string>
items · string
pattern: ^[a-z][a-z0-9_]{0,63}$
denied_tracks · array<string>
items · string
pattern: ^[a-z][a-z0-9_]{0,63}$
blob_presign_scope · object
Scope limiter for ak.self.blob.command.presign.v1 grants: allowed purposes plus optional blob/realm restrictions.
* allowed_purposes · array<string (enum)>
items · …
recursion truncated at depth 8; see source schema for full shape
blob_ref_pattern · string
realm_ids · array<$ref ./common-ids.schema.json#/$defs/realm_id>
items · …
recursion truncated at depth 8; see source schema for full shape
allowed_data_labels · array<string>
Data classification labels this grant may read, export, transform, or send to external endpoints.
items · string
pattern: ^[a-z][a-z0-9_]{0,63}$
allowed_endpoints · array<string>
Allowed outbound endpoint origins or deployment-approved endpoint patterns for applet / agent / connector operations.
items · string
max_authority_depth · integer
Maximum remaining authority hops. Bounded by the canonical authority-chain depth ceiling (4) defined in zh/conformance/scalability-constraints.md §3 and zh/authz/capabilities.md §10.2; reducers MUST reject grants declaring a larger value at accept time rather than only truncating during DFS.
authority_path_ids · array<$ref ./common-ids.schema.json#/$defs/did_core_id>
items · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
authority_regrant_allowed · boolean
authority_scope · string (enum)
enum: "narrowing_only" "same_scope" "custom"
applet_id · string · $ref ./common-ids.schema.json#/$defs/applet_id
Stable canonical Applet installation identity. Applet service authority is carried separately by service_id.
pattern: ^ak:applet:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$
executed_by · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind · …
recursion truncated at depth 8; see source schema for full shape
* account_id · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* kind · …
recursion truncated at depth 8; see source schema for full shape
* service_id · …
recursion truncated at depth 8; see source schema for full shape
registration_epoch · string
authority_control(constraint_subkind=applet_authority) binding to the canonical Applet registration epoch.
pattern: ^sha256:[0-9a-f]{64}$
blob_max_bytes · integer
blob_presign_max_ttl_seconds · integer
Maximum TTL, in seconds, that this grant permits for ak.blob.presign. The service must clamp requested max_age_seconds to the smaller of this value and deployment policy.
max_total_blob_bytes · integer
max_artifact_bytes · integer
Maximum artifact size in bytes for applet / agent / export operations.
max_operations · integer
Maximum number of distinct accepted idempotency identities in one UTC epoch-aligned fixed period. Enforcement is a linearizable check-and-reserve at one logical quota authority shared by every node in the enforcing service; per-node duplicated budgets and overshoot are forbidden.
period · string
ISO 8601 duration. For quota constraints, a stricter conditional schema permits only a non-zero fixed-length week/day/hour/minute/second duration; year/month durations are forbidden so every authority derives the same UTC epoch-aligned window id.
pattern: ^P(?:[0-9]+Y)?(?:[0-9]+M)?(?:[0-9]+W)?(?:[0-9]+D)?(?:T(?:[0-9]+H)?(?:[0-9]+M)?(?:[0-9]+S)?)?$
burst · integer
Optional token-bucket capacity at the same logical quota authority, capped by max_operations and refilled at max_operations/period. It never increases the fixed-window total budget.
constraint_scope · string (enum)
Closed v1 quota counting scope. Unknown values are schema violations and MUST fail closed. Quota counters are actor-bound; the enum selects the additional slicing dimension: actor only, actor+space, actor+realm, or actor across all nodes/regions of the enforcing service's global quota domain. global is not an implicit federation-wide counter. Every node in the service domain MUST share one logical linearizable quota authority.
enum: "per_actor" "per_space" "per_realm" "global"
max_resources · integer
resource_kind · string
approval_required · boolean
approval_mode · string (enum)
The only approval mode of v1. The approved write MUST NOT take effect before the approval evidence is verified and accepted in the same transaction (zh/authz/constraint-schema.md section 9.2.7). There is no second mode and no path that first materializes a proposal object and then approves that object.
enum: "before_commit"
approval_actor_ids · array<$ref ./common-ids.schema.json#/$defs/did_core_id>
items · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
approval_relation · string (enum)
Responsibility classification of this grant explicit approval_actor_ids roster. It never creates a second dynamic roster or supplies action/scope capability. Missing explicit roster cannot satisfy approval.
enum: "responsible" "controller" "guardian" "realm_admin" "custom"
timeout · string
Positive fixed ISO 8601 duration (week/day/hour/minute/second, no calendar year/month). Each approval vote is valid only when the target covering committed_at <= that vote input.approved_at + timeout, inclusive and with zero tolerance. The same rule applies to Event and operation targets; receiver clocks and first-seen timestamps never anchor it. Omission adds no grant-local age limit.
pattern: ^P(?:[0-9]+Y)?(?:[0-9]+M)?(?:[0-9]+W)?(?:[0-9]+D)?(?:T(?:[0-9]+H)?(?:[0-9]+M)?(?:[0-9]+S)?)?$
approval_threshold · oneOf[2]
Closed executable vote threshold: majority means floor(N/2)+1, unanimous means N, and a positive integer is the exact quorum. N is the distinct eligible approver set at the accepting authority cut. Omission means unanimous. A missing or empty eligible set, or an integer greater than N, cannot satisfy approval. Repeated signatures by one approver count once. Parameterless quorum/custom strings are schema violations.
example: "unanimous"
oneOf · oneOf[0] · string (enum)
enum: "majority" "unanimous"
oneOf · oneOf[1] · integer
accountability_required · boolean
guardian_approval_required · boolean
controller_approval_required · boolean
required_claims · array<object>
Conditional claim requirements. resource-selector-grammar.md §3.3 caps this array at 32 entries as a normative DoS guard; the schema enforces maxItems:32 so condition-selector grants cannot smuggle in unbounded claim objects.
items · object
anyOf · anyOf[0] · …
recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[1] · …
recursion truncated at depth 8; see source schema for full shape
* claim_kind · …
recursion truncated at depth 8; see source schema for full shape
issuer_id · …
recursion truncated at depth 8; see source schema for full shape
trusted_issuer_ids · …
recursion truncated at depth 8; see source schema for full shape
subject_matches_actor · …
recursion truncated at depth 8; see source schema for full shape
value_constraints · …
recursion truncated at depth 8; see source schema for full shape
organization_id · …
recursion truncated at depth 8; see source schema for full shape
status · …
recursion truncated at depth 8; see source schema for full shape
roles · …
recursion truncated at depth 8; see source schema for full shape
trusted_claim_issuer_ids · array<$ref ./common-ids.schema.json#/$defs/did_core_id>
items · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
claim_refresh_required · boolean
claim_max_age · string
pattern: ^P(?:[0-9]+Y)?(?:[0-9]+M)?(?:[0-9]+W)?(?:[0-9]+D)?(?:T(?:[0-9]+H)?(?:[0-9]+M)?(?:[0-9]+S)?)?$
allowed_history_access_values · array<string (enum)>
items · string (enum)
enum: "since_join" "all_history_for_current_members"
redacted_history_allowed · boolean
encryption_required · boolean
min_encryption_level · string (enum)
confidentiality(constraint_subkind=encryption) static floor: the minimum content-encryption mechanism the grant requires. Pure static declaration evaluated as stateless unless cross-checked against the scope's current MLS activation state (see constraint-schema.md section 12).
enum: "none" "mls_rfc9420" "external"
plaintext_fallback_allowed · boolean
confidentiality(constraint_subkind=encryption) static flag: whether the grant permits plaintext in a scope that has no accepted ak.mls.genesis. After activation the flag cannot restore plaintext; the write MUST be rejected with mls_activation_irreversible. See constraint-schema.md §12.
audit_trail_required · boolean
confidentiality(constraint_subkind=encryption) static flag: whether the grant requires an audit trail (e.g. active Audit Applet Binding). See constraint-schema.md §12.
key_rotation_period · string
pattern: ^P(?:[0-9]+Y)?(?:[0-9]+M)?(?:[0-9]+W)?(?:[0-9]+D)?(?:T(?:[0-9]+H)?(?:[0-9]+M)?(?:[0-9]+S)?)?$
max_key_age · string
pattern: ^P(?:[0-9]+Y)?(?:[0-9]+M)?(?:[0-9]+W)?(?:[0-9]+D)?(?:T(?:[0-9]+H)?(?:[0-9]+M)?(?:[0-9]+S)?)?$
key_backup_required · boolean
approved_key_issuer_ids · array<$ref ./common-ids.schema.json#/$defs/did_core_id>
items · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
depends_on_moderation_state · boolean
Cache-invalidation hint: when true, this grant's authorization decisions depend on the moderation_state typed current result (see capabilities.md §18.1) and the grant's cache entry MUST be invalidated when that typed current result changes. Default false: ordinary grants (ak.strand.update / ak.message.create / organization membership grants) do NOT take a cache hit on every moderation decision. v1 capabilities.md §18.1 lists three conditions where MUST be explicitly true (moderator-role grants, condition-selector subjects referencing moderation state, constraints referencing moderation queue / typed current result). Schema-side enforcement of condition (2) is in capability-grant.schema.json via if/then on actions[]; conditions (1) and (3) are reducer-side lint. Cache invalidation hint outside the eight constraint families; it does not participate in allow/deny evaluation and is documented in capabilities.md §6 / constraint-schema.md.
allowed_managed_actor_roles · array<string (enum)>
Ordinary authority_control permits only these accepted roles of the Applet bound by the parent applet_authority constraint; no arbitrary third-party regrant.
items · string (enum)
enum: "bot" "ghost"
(^x_[a-z][a-z0-9_]{0,63}$) · any
* issued_at · string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
* status · string (enum)
Reducer-derived lifecycle status of this Grant (zh/authz/capabilities.md section 12.1). It is absent from the closed authoring body of ak.capability.grant and is materialised by the registered capability_status derivation, so an author-supplied value MUST be rejected rather than trusted. The two terminal values stay distinct because section 10.4 gives them different authorities: revoke is issuer or root-controller authority, relinquish is the target subject's own signature and MUST NOT require ak.capability.revoke. Collapsing them into revoked_at alone would erase which authority closed the Grant. A terminal value is final -- section 12.1 forbids resurrecting a closed grant_id -- and compaction MUST preserve it.
enum: "active" "revoked" "relinquished"
updated_by · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind · const "account"
enum: "account"
* account_id · $ref #/$defs/account_id · $ref #/$defs/account_id
oneOf · oneOf[1] · object
* kind · const "service"
enum: "service"
* service_id · $ref #/$defs/did_core_id · $ref #/$defs/did_core_id
updated_at · string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
revoked_by · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind · const "account"
enum: "account"
* account_id · $ref #/$defs/account_id · $ref #/$defs/account_id
oneOf · oneOf[1] · object
* kind · const "service"
enum: "service"
* service_id · $ref #/$defs/did_core_id · $ref #/$defs/did_core_id
revoked_at · $ref #/$defs/timestamp · $ref #/$defs/timestamp
* issuer_authority_refs · array<oneOf[3]>
The signed semantic authority lineage this grant was issued under. A root controller's grant anchors on the accepted Realm authority Event; any further grant anchors on grants its issuer already holds. These closed refs intentionally carry no producer-selected current-result revision, authorization-state digest, Station id or commit basis: the governing Station resolves their current typed results at acceptance, fails closed when current authority cannot be proved fresh, and records the accepting RealmCommit as the decision basis. Authorization is recomputed from these refs on every decision, so revoking an ancestor invalidates its descendants without a cascading write. The sole owned_agent ref is an explicit non-regrant exception; it pins ownership membership and continuously bounds the Agent by current controller authority.
items · oneOf[3]
oneOf · oneOf[0] · object
A grant the issuer holds. The issuer MUST be that grant's subject, and the ref MUST be active both at acceptance and evaluation time; its capability, resources and constraints all bound this child. Its current-result revision is an acceptance-time Station input, not a signed wire member.
* kind · const "grant"
enum: "grant"
* grant_id · string · $ref ./common-ids.schema.json#/$defs/grant_id
pattern: ^ak:grant:[A-Za-z0-9_-]{44}$
oneOf · oneOf[1] · object
A committed authority root in the same Realm as the grant. It is terminal for cycle checks. The accepting Station verifies the named Event/controller/generation against durable current authority; the ref does not carry a Station-local commit wrapper.
* kind · const "realm_root"
enum: "realm_root"
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* authority_event_ref · string · $ref ./common-ids.schema.json#/$defs/event_id
Complete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern: ^ak:event:[A-Za-z0-9_-]{44}$
* authority_generation · integer
Realm authority-root delegation generation at issuance, read from the realm_authority_root typed current result. A ref stays valid only while that value's current authority_generation still equals this one, and the read MUST use the registered inclusion proof at a RealmCommit basis, never an unproven cache. ak.realm.authority.reset is the only kind that advances it, so it is the only act that invalidates a whole delegated generation; ak.realm.owner.transfer preserves it and therefore leaves every child grant valid. This is NOT the governing Station tenure, which is governance_generation on RealmCommit -- a planned Station handoff MUST NOT invalidate any grant.
oneOf · oneOf[2] · $ref #/$defs/owned_agent_authority_ref · $ref #/$defs/owned_agent_authority_ref
* authority_depth · integer
Reducer-derived absolute distance from the authority root: a realm_root ref counts 0, so a root controller's grant is 1 and a member's re-grant is 2. Derived from the refs, never author-declared, so it cannot be misreported — which is what makes it safe to answer 'how far did this authority spread' with a single field instead of a recursive join. Taken at issuance and not recomputed on revocation; a later chain may be shorter than the recorded value, which is the conservative direction for a max_authority_depth decision. A dedicated terminal owned_agent source has depth 1 and cannot become a parent grant.
* authority_root_refs · array<oneOf[2]>
Reducer-derived set of committed authority roots this grant ultimately descends from: direct realm_root refs plus the union of every parent grant's roots. Deduplicated on (realm_id, authority_event_ref, authority_generation) and sorted canonically by unsigned-byte order. For an owned_agent source the sole root is that exact owned_agent ref; it never confers Realm root-control authority.
items · oneOf[2]
oneOf · oneOf[0] · object
* kind · const "realm_root"
enum: "realm_root"
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* authority_event_ref · string · $ref ./common-ids.schema.json#/$defs/event_id
Complete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern: ^ak:event:[A-Za-z0-9_-]{44}$
* authority_generation · integer
The delegation generation of the root this grant descends from, carried verbatim from the realm_root ref. Part of the dedup key, because the same root at a different generation is a different authority.
oneOf · oneOf[1] · $ref #/$defs/owned_agent_authority_ref · $ref #/$defs/owned_agent_authority_ref
(^x_[a-z][a-z0-9_]{0,63}$) · any
* revision · object · $ref ./typed-current-result.schema.json#/$defs/revision
* commit_id · string · $ref ./common-ids.schema.json#/$defs/realm_commit_id
Content-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern: ^ak:realm_commit:[A-Za-z0-9_-]{44}$
* stream_position · integer
* state_digest · string
Digest of the complete effective-list snapshot. It MUST NOT be copied into expected_revision or otherwise treated as one grant's revision.
pattern: ^(sha256|blake3):[0-9a-f]{64}$
* evaluated_at · string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
anyOf · anyOf[29] · object · $ref #/$defs/IdentityDocumentView
Result of ak.root.identity.document.resource.get.v1 — current DID Document plus normalized view hints.
* did_document · object
Raw DID Core document with W3C field names preserved.
normalized_view · object
Optional Arkret normalized principal view (snake_case) — derived projection only, NOT a re-publishable DID Document. See zh/identity/identity-did.md §6.
method_evidence · oneOf[3] · $ref ./identity-resolution.schema.json#/$defs/method_history_evidence
Adapter-routed evidence. evidence_kind is the single-source discriminator: the receiver resolves it through did-method-adapter-registry.json method_evidence_kind, which is unique across active adapters, to exactly one active adapter for this versioned schema. The evidence carries no adapter_version; an adapter change requires a new schema/operation version rather than a registry drift under the same wire shape. Unknown evidence kinds fail closed.
oneOf · oneOf[0] · $ref #/$defs/webvh_method_history_evidence · $ref #/$defs/webvh_method_history_evidence
oneOf · oneOf[1] · $ref #/$defs/did_web_method_history_evidence · $ref #/$defs/did_web_method_history_evidence
oneOf · oneOf[2] · $ref #/$defs/did_key_method_history_evidence · $ref #/$defs/did_key_method_history_evidence
cached_at · string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
anyOf · anyOf[30] · object · $ref #/$defs/IdentityLogListOutcome
Result of ak.root.identity.log.read.list.v1. Entries are returned in the DID method's own native log form: for did:webvh each entry is a verbatim did.jsonl log entry with its native versionId, entryHash chain and Data Integrity proof. Arkret defines no parallel entry envelope, sequence numbering, hash chain or proof transcript over DID logs — the method already provides all of them, and a second signed representation of the same history could disagree with the first. Methods without a native history (did:web) MUST report that rather than being wrapped in a shape that implies one.
* did · string · $ref ./common-ids.schema.json#/$defs/did
Canonical bare DID used for registration, DID method resolution and owner-published current resolution. It contains no path, query or fragment and MUST project through the registered method adapter to exactly one did_core_id.
pattern: ^did:[a-z0-9]+:[^\s/?#]+$
* method · string
DID method of the returned log, e.g. did:webvh. Consumers dispatch parsing and verification on this value.
native_history · boolean
False when the method has no native key history at all (did:web). Such a response MUST return an empty entries array; the server MUST NOT synthesise entries, sequence numbers or a chain the method does not have.
* entries · array<object>
Verbatim method-native log entries in method order. Arkret does not reinterpret, renumber or re-sign them; verification follows the method specification.
items · object
next_cursor · string
Opaque continuation cursor for the next page when has_more=true.
* has_more · boolean
anyOf · anyOf[31] · object · $ref #/$defs/IdentityReceiptListOutcome
Result of ak.root.identity.receipts.read.list.v1. receipts[] is a tagged union over two distinct object families discriminated by their schema constant: ak.schema.identity_receipt.v1 records a role inside a DID registry consensus group (writer / witness / replica) and binds seq + accepted_entry_digest, while ak.schema.did_webvh_witness_receipt.v1 records a did:webvh method witness observed at a specific versionId. The two say different things with the same English word, so the discriminator is mandatory and a verifier MUST branch on it rather than infer intent from which optional fields happen to be present.
* receipts · array<oneOf[2]>
items · oneOf[2]
oneOf · oneOf[0] · object · $ref ./identity-receipt.schema.json
* schema · const "ak.schema.identity_receipt.v1"
Canonical schema discriminator. Aligned with schema-registry.json; lets validators distinguish identity registry receipts from other receipt envelopes (e.g. audit-ryw-receipt, event-batch-receipt).
enum: "ak.schema.identity_receipt.v1"
* receipt_id · string
pattern: ^ak:receipt:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$
* subject_did · string · $ref ./common-ids.schema.json#/$defs/did
Canonical bare DID used for registration, DID method resolution and owner-published current resolution. It contains no path, query or fragment and MUST project through the registered method adapter to exactly one did_core_id.
pattern: ^did:[a-z0-9]+:[^\s/?#]+$
* seq · integer
* accepted_entry_digest · string
SHA-256 of RFC 8785 JCS of the exact complete accepted method-native log entry, including its control proofs. It commits to immutable accepted bytes at subject_did and seq, not a PCR Event or an unsigned-operation projection. Receipts with different digests at the same position MUST NOT contribute to the same consensus quorum.
pattern: ^sha256:[0-9a-f]{64}$
* registry_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* witness_role · string (enum)
Issuer's role in the DID registry consensus group. Required so verifiers can apply role-specific freshness / quorum rules; an absent role would force the verifier to guess writer vs replica semantics.
enum: "writer" "witness" "replica"
audience · string
Optional audience binding (verifier DID, service DID, or domain). When present, verifiers MUST reject the receipt outside that audience context to prevent cross-protocol reuse.
* created_at · $ref #/$defs/timestamp · $ref #/$defs/timestamp
* signature · object · $ref ./event-envelope.schema.json#/$defs/proof
Generic detached-JWS proof shape reused by non-Event schemas (snapshot signature, snapshot witness attestations, identity receipts, handle claims, etc.). MUST NOT be used as the shape of Event Envelope `producer_proof` — Event proofs reference $defs/event_proof and bind canonical Event bytes via `event_digest`. Non-Event signed objects MUST define an object-family signing-context constant and include it in the canonical proof binding object with payload_digest; the context constant is not a wire field in this generic shape. drift detection: `payload_digest#event_proof` in forbidden-wire-fields.json is the hard-reject mirror of this rule. New non-Event signed objects MAY $ref this shape; new signed Event-shaped objects MUST instead $ref event_proof.
* kind · string (enum)
Generic detached JWS proof over a canonical non-Event payload binding object that includes an object-family context constant.
enum: "detached_jws"
* verification_method · string
DID URL of the signing key for this non-Event detached proof. Same pattern as $defs/event_proof.verification_method; semantics are decoupled from Event proof (see $defs/event_proof for the Event-only shape).
pattern: ^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$
* payload_digest · $ref #/$defs/digest · $ref #/$defs/digest
Generic non-Event detached-proof hash. This $defs/proof shape is reused by non-Event schemas; Event.properties.producer_proof references $defs/event_proof and MUST use event_digest instead.
* created_at · $ref #/$defs/timestamp · $ref #/$defs/timestamp
domain · string
audience · oneOf[2]
oneOf · oneOf[0] · string
oneOf · oneOf[1] · array<string>
items · string
proof_purpose · string (enum)
Optional role discriminator for non-Event proofs. HandleClaim core, status and revocation carriers make issuer_attestation, holder_acceptance, status_attestation and revocation_authorization load-bearing. governance_authorization marks a resource-governance-key authorization (directory withdraw/takedown-appeal, discovery-directory.md 8.7.1). Generic proof consumers ignore it unless their object-family contract makes it load-bearing.
enum: "issuer_attestation" "holder_acceptance" "status_attestation" "revocation_authorization" "governance_authorization"
* jws · string
pattern: ^[A-Za-z0-9_-]+\.\.[A-Za-z0-9_-]+$
oneOf · oneOf[1] · object · $ref ./did-webvh-witness-receipt.schema.json
Arkret-layer, cacheable and auditable record that a named did:webvh witness was observed attesting a specific log version. It is deliberately a separate object family from ak.schema.identity_receipt.v1: that one records a role (writer / witness / replica) inside a DID registry consensus group and binds seq + accepted_entry_digest, whereas this one binds a did:webvh method versionId and a witness did:key drawn from parameters.witness. Overloading one object with both meanings would leave half its required fields meaningless on either branch and force verifiers to guess which sense of the word witness applies. This receipt NEVER substitutes for method conformance: a verifier MUST still fetch and verify the standard did-witness.json proofs, the entry hash chain and the controller proof. See zh/identity/identity-did.md.
* schema · const "ak.schema.did_webvh_witness_receipt.v1"
Closed discriminator. ak.root.identity.receipts.read.list.v1 returns a tagged union of receipt families; this constant is what lets a verifier pick the did:webvh method-witness branch instead of the registry consensus branch without guessing.
enum: "ak.schema.did_webvh_witness_receipt.v1"
* receipt_id · string
pattern: ^ak:receipt:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$
* subject_did · string · $ref ./common-ids.schema.json#/$defs/webvh_did
Canonical bare did:webvh identifier used at method-native registration, document and evidence boundaries. Role admission is enforced separately.
pattern: ^did:webvh:[^\s:/?#]+:[^\s/?#]+$
* version_id · string
The exact did:webvh versionId this attestation covers, verbatim from the log entry. Binding to versionId rather than to a digest of the document is what makes the receipt replayable against did-witness.json, whose proofs are themselves keyed by versionId.
pattern: ^(?!ak:)
log_head_digest · string
Optional digest of the log head the issuer held when observing. Present it when the issuer can commit to the whole log state; it lets a consumer detect a split view that a per-version binding alone would not reveal.
pattern: ^(sha256|blake3):[0-9a-f]{64}$
* witness_did · string · $ref ./common-ids.schema.json#/$defs/did_key_did
Canonical bare did:key identifier used at method-native key and witness evidence boundaries. This is a registered method-specific Did subtype, not a business ActorId and not a DID URL.
pattern: ^did:key:z[1-9A-HJ-NP-Za-km-z]+$
* witness_verification_method · string
The specific verification method inside witness_did whose signature appears in did-witness.json for version_id.
pattern: ^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$
* controlling_organization_did · string · $ref ./common-ids.schema.json#/$defs/did
Canonical bare DID used for registration, DID method resolution and owner-published current resolution. It contains no path, query or fragment and MUST project through the registered method adapter to exactly one did_core_id.
pattern: ^did:[a-z0-9]+:[^\s/?#]+$
* observed_at · $ref #/$defs/timestamp · $ref #/$defs/timestamp
When the issuer actually fetched or observed the witness proof. Freshness is evaluated against this instant, not against created_at: an issuer could otherwise re-sign a years-old observation and present it as current.
source_url · string (uri) · format=uri
Optional origin the proof was read from (the DID's own did-witness.json or a declared mirror). Recorded so a consumer can tell a first-party read from a mirrored one when adjudicating conflicting receipts.
pattern: ^https://
* issuer_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
trust_domain · string · $ref ./common-ids.schema.json#/$defs/trust_domain
Optional trust domain the receipt is scoped to.
pattern: ^ak:trust_domain:[a-z0-9][a-z0-9._\-:]{0,127}$
audience · string
Optional audience binding (verifier DID, service DID, or domain). When present, verifiers MUST reject the receipt outside that audience context to prevent cross-protocol reuse.
* expires_at · $ref #/$defs/timestamp · $ref #/$defs/timestamp
Required. An Arkret-layer cache record without an expiry becomes indistinguishable from a permanent assertion, which is precisely how stale witness evidence outlives the state it described. MUST be later than created_at, and a consumer MUST treat an expired receipt as absent rather than as weak evidence.
* created_at · $ref #/$defs/timestamp · $ref #/$defs/timestamp
* signature · object · $ref ./event-envelope.schema.json#/$defs/proof
Generic detached-JWS proof shape reused by non-Event schemas (snapshot signature, snapshot witness attestations, identity receipts, handle claims, etc.). MUST NOT be used as the shape of Event Envelope `producer_proof` — Event proofs reference $defs/event_proof and bind canonical Event bytes via `event_digest`. Non-Event signed objects MUST define an object-family signing-context constant and include it in the canonical proof binding object with payload_digest; the context constant is not a wire field in this generic shape. drift detection: `payload_digest#event_proof` in forbidden-wire-fields.json is the hard-reject mirror of this rule. New non-Event signed objects MAY $ref this shape; new signed Event-shaped objects MUST instead $ref event_proof.
* kind · string (enum)
Generic detached JWS proof over a canonical non-Event payload binding object that includes an object-family context constant.
enum: "detached_jws"
* verification_method · string
DID URL of the signing key for this non-Event detached proof. Same pattern as $defs/event_proof.verification_method; semantics are decoupled from Event proof (see $defs/event_proof for the Event-only shape).
pattern: ^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$
* payload_digest · $ref #/$defs/digest · $ref #/$defs/digest
Generic non-Event detached-proof hash. This $defs/proof shape is reused by non-Event schemas; Event.properties.producer_proof references $defs/event_proof and MUST use event_digest instead.
* created_at · $ref #/$defs/timestamp · $ref #/$defs/timestamp
domain · string
audience · oneOf[2]
oneOf · oneOf[0] · string
oneOf · oneOf[1] · array<string>
items · string
proof_purpose · string (enum)
Optional role discriminator for non-Event proofs. HandleClaim core, status and revocation carriers make issuer_attestation, holder_acceptance, status_attestation and revocation_authorization load-bearing. governance_authorization marks a resource-governance-key authorization (directory withdraw/takedown-appeal, discovery-directory.md 8.7.1). Generic proof consumers ignore it unless their object-family contract makes it load-bearing.
enum: "issuer_attestation" "holder_acceptance" "status_attestation" "revocation_authorization" "governance_authorization"
* jws · string
pattern: ^[A-Za-z0-9_-]+\.\.[A-Za-z0-9_-]+$
threshold_met · boolean
True when the returned receipt set satisfies the effective witness threshold for the requested head. The effective threshold is the strictest intersection of the method-native parameters.witness.threshold and the deployment / Realm policy minimum (identity-did.md §3.4.2), and distinctness is counted over controlling_organization_did where policy requires distinct organizations. Omitted when the registry cannot evaluate threshold policy for this query; an omitted value MUST NOT be read as true. A true value is an Arkret-layer convenience and MUST NOT replace verifying the standard did-witness.json proofs.
anyOf · anyOf[32] · object · $ref #/$defs/IdentityResolveOutcome
did_document · object
key_log_head · string · $ref ./account-operations.schema.json#/$defs/digest
pattern: ^(sha256|blake3):[0-9a-f]{64}$
seq · integer
method_evidence · oneOf[1] · $ref #/$defs/IdentityMethodEvidence
oneOf · oneOf[0] · object · $ref #/$defs/DidWebvhIdentityMethodEvidence
Method-native pins derived only after fail-closed verification of the complete did:webvh history. control_key_digest is SHA-256 over the decoded canonical multikey bytes of parameters.updateKeys[0] at version_id.
* kind · const "did_webvh"
enum: "did_webvh"
* version_id · string
pattern: ^(?!ak:)
* control_key_digest · string
pattern: ^sha256:[0-9a-f]{64}$
receipts · array<$ref ./identity-receipt.schema.json>
items · object · $ref ./identity-receipt.schema.json
* schema · const "ak.schema.identity_receipt.v1"
Canonical schema discriminator. Aligned with schema-registry.json; lets validators distinguish identity registry receipts from other receipt envelopes (e.g. audit-ryw-receipt, event-batch-receipt).
enum: "ak.schema.identity_receipt.v1"
* receipt_id · string
pattern: ^ak:receipt:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$
* subject_did · string · $ref ./common-ids.schema.json#/$defs/did
Canonical bare DID used for registration, DID method resolution and owner-published current resolution. It contains no path, query or fragment and MUST project through the registered method adapter to exactly one did_core_id.
pattern: ^did:[a-z0-9]+:[^\s/?#]+$
* seq · integer
* accepted_entry_digest · string
SHA-256 of RFC 8785 JCS of the exact complete accepted method-native log entry, including its control proofs. It commits to immutable accepted bytes at subject_did and seq, not a PCR Event or an unsigned-operation projection. Receipts with different digests at the same position MUST NOT contribute to the same consensus quorum.
pattern: ^sha256:[0-9a-f]{64}$
* registry_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* witness_role · string (enum)
Issuer's role in the DID registry consensus group. Required so verifiers can apply role-specific freshness / quorum rules; an absent role would force the verifier to guess writer vs replica semantics.
enum: "writer" "witness" "replica"
audience · string
Optional audience binding (verifier DID, service DID, or domain). When present, verifiers MUST reject the receipt outside that audience context to prevent cross-protocol reuse.
* created_at · $ref #/$defs/timestamp · $ref #/$defs/timestamp
* signature · object · $ref ./event-envelope.schema.json#/$defs/proof
Generic detached-JWS proof shape reused by non-Event schemas (snapshot signature, snapshot witness attestations, identity receipts, handle claims, etc.). MUST NOT be used as the shape of Event Envelope `producer_proof` — Event proofs reference $defs/event_proof and bind canonical Event bytes via `event_digest`. Non-Event signed objects MUST define an object-family signing-context constant and include it in the canonical proof binding object with payload_digest; the context constant is not a wire field in this generic shape. drift detection: `payload_digest#event_proof` in forbidden-wire-fields.json is the hard-reject mirror of this rule. New non-Event signed objects MAY $ref this shape; new signed Event-shaped objects MUST instead $ref event_proof.
* kind · string (enum)
Generic detached JWS proof over a canonical non-Event payload binding object that includes an object-family context constant.
enum: "detached_jws"
* verification_method · string
DID URL of the signing key for this non-Event detached proof. Same pattern as $defs/event_proof.verification_method; semantics are decoupled from Event proof (see $defs/event_proof for the Event-only shape).
pattern: ^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$
* payload_digest · $ref #/$defs/digest · $ref #/$defs/digest
Generic non-Event detached-proof hash. This $defs/proof shape is reused by non-Event schemas; Event.properties.producer_proof references $defs/event_proof and MUST use event_digest instead.
* created_at · $ref #/$defs/timestamp · $ref #/$defs/timestamp
domain · string
audience · oneOf[2]
oneOf · oneOf[0] · string
oneOf · oneOf[1] · array<string>
items · string
proof_purpose · string (enum)
Optional role discriminator for non-Event proofs. HandleClaim core, status and revocation carriers make issuer_attestation, holder_acceptance, status_attestation and revocation_authorization load-bearing. governance_authorization marks a resource-governance-key authorization (directory withdraw/takedown-appeal, discovery-directory.md 8.7.1). Generic proof consumers ignore it unless their object-family contract makes it load-bearing.
enum: "issuer_attestation" "holder_acceptance" "status_attestation" "revocation_authorization" "governance_authorization"
* jws · string
pattern: ^[A-Za-z0-9_-]+\.\.[A-Za-z0-9_-]+$
anyOf · anyOf[33] · object · $ref #/$defs/IdentityResolveRequestBody
* did · string · $ref ./common-ids.schema.json#/$defs/did
Canonical bare DID used for registration, DID method resolution and owner-published current resolution. It contains no path, query or fragment and MUST project through the registered method adapter to exactly one did_core_id.
pattern: ^did:[a-z0-9]+:[^\s/?#]+$
requested_evidence_kinds · array<string (enum)>
items · string (enum)
enum: "did_webvh"
anyOf · anyOf[34] · object · $ref #/$defs/InitialSessionGrantIntent
Initial Standard SessionGrant intent embedded in identity_creation registration. It reuses the DPoP holder key established by account handoff; Account Authority recomputes RFC 7638 thumbprint of session_public_key and requires equality with the handoff/control-proof dpop_jkt. It is not a separate authorization or credential.
* device_id · string · $ref ./common-ids.schema.json#/$defs/device_id
pattern: ^ak:device:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$
* session_public_key · string (canonical-public-jwk-jcs) · format=canonical-public-jwk-jcs
Exact RFC 8785 JCS public JWK for the existing handoff DPoP holder key. Private members are forbidden.
* audience_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
anyOf · anyOf[35] · object · $ref #/$defs/MlsGroupStateMaterialOutcome
Exact RFC 9420 public group-state material. *_bytes_b64 use unpadded base64url. Consumers MUST decode each content-addressed Blob ref's embedded suite, hash the raw bytes under that suite, compare the digest, verify GroupInfo and ratchet_tree consistency, then derive leaf_index only from occupied leaves in the verified tree. Blob suites are independent of the fixed SHA-256 Event/RealmCommit identity suite.
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* effective_scope · oneOf[3] · $ref ./event-payload.schema.json#/$defs/effective_scope
oneOf · oneOf[0] · object
* kind · const "realm"
enum: "realm"
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
oneOf · oneOf[1] · object
* kind · const "circle"
enum: "circle"
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* circle_id · string · $ref ./common-ids.schema.json#/$defs/circle_id
pattern: ^ak:circle:[A-Za-z0-9_-]{44}$
oneOf · oneOf[2] · object
* kind · const "sidecar"
enum: "sidecar"
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* sidecar_id · string · $ref ./common-ids.schema.json#/$defs/sidecar_id
pattern: ^ak:sidecar:[A-Za-z0-9_-]{44}$
* mls_group_id · string · $ref ./common-ids.schema.json#/$defs/mls_group_id
RFC 9420 group_id as base64url_no_pad(SHA-256(UTF8("ak.mls.group_id.v1") || 0x00 || canonical_effective_scope_key_bytes(effective_scope))), so exactly 43 characters. Derived by the reducer and the SDK from the effective scope alone; actors never submit it. The v1 formula is the only one: the earlier reversible base64url of the scope key bytes MUST NOT be accepted alongside it. See zh/models/realm-and-space.md section 2.2.
pattern: ^[A-Za-z0-9_-]{43}$
* epoch · const 0
enum: 0
* group_state_event_id · string · $ref #/$defs/EventId
pattern: ^ak:event:[A-Za-z0-9_-]{44}$
* group_info_ref · string
Copied byte-for-byte from the accepted ak.mls.genesis payload; the embedded Blob digest suite is the sole wire carrier of the material digest and is independent of the fixed SHA-256 Event/RealmCommit identity suite (encoding.md 4.0.1).
pattern: ^ak:blob:(?:sha256|blake3):[0-9a-f]{64}$
* group_info_bytes_b64 · string
pattern: ^[A-Za-z0-9_-]+$
* ratchet_tree_ref · string
Copied byte-for-byte from the accepted ak.mls.genesis payload; the embedded Blob digest suite is the sole wire carrier of the material digest and is independent of the fixed SHA-256 Event/RealmCommit identity suite (encoding.md 4.0.1).
pattern: ^ak:blob:(?:sha256|blake3):[0-9a-f]{64}$
* ratchet_tree_bytes_b64 · string
pattern: ^[A-Za-z0-9_-]+$
anyOf · anyOf[36] · object · $ref #/$defs/MlsGroupStateMaterialRequestBody
Read-only service request for the exact public MLS epoch-0 GroupInfo and ratchet_tree bytes committed by one accepted ak.mls.genesis Event. Every Genesis selector is copied from that Event. When caller_actor_id is present, target_commit_event_ref and target_epoch are mandatory; governance checks current and target-cut member/history authority and source Station replication right at the target accepted Commit cut. Without caller_actor_id this remains the original Station replication-only read, with source Station replication right checked at the Genesis Commit position.
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* effective_scope · oneOf[3] · $ref ./event-payload.schema.json#/$defs/effective_scope
oneOf · oneOf[0] · object
* kind · const "realm"
enum: "realm"
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
oneOf · oneOf[1] · object
* kind · const "circle"
enum: "circle"
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* circle_id · string · $ref ./common-ids.schema.json#/$defs/circle_id
pattern: ^ak:circle:[A-Za-z0-9_-]{44}$
oneOf · oneOf[2] · object
* kind · const "sidecar"
enum: "sidecar"
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* sidecar_id · string · $ref ./common-ids.schema.json#/$defs/sidecar_id
pattern: ^ak:sidecar:[A-Za-z0-9_-]{44}$
* mls_group_id · string · $ref ./common-ids.schema.json#/$defs/mls_group_id
RFC 9420 group_id as base64url_no_pad(SHA-256(UTF8("ak.mls.group_id.v1") || 0x00 || canonical_effective_scope_key_bytes(effective_scope))), so exactly 43 characters. Derived by the reducer and the SDK from the effective scope alone; actors never submit it. The v1 formula is the only one: the earlier reversible base64url of the scope key bytes MUST NOT be accepted alongside it. See zh/models/realm-and-space.md section 2.2.
pattern: ^[A-Za-z0-9_-]{43}$
* epoch · const 0
enum: 0
* group_state_event_id · string · $ref #/$defs/EventId
pattern: ^ak:event:[A-Za-z0-9_-]{44}$
caller_actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind · const "account"
enum: "account"
* account_id · $ref #/$defs/account_id · $ref #/$defs/account_id
oneOf · oneOf[1] · object
* kind · const "service"
enum: "service"
* service_id · $ref #/$defs/did_core_id · $ref #/$defs/did_core_id
target_commit_event_ref · string · $ref #/$defs/EventId
pattern: ^ak:event:[A-Za-z0-9_-]{44}$
target_epoch · integer
* group_info_ref · string
Copied byte-for-byte from the accepted ak.mls.genesis payload; the embedded Blob digest suite is the sole wire carrier of the material digest and is independent of the fixed SHA-256 Event/RealmCommit identity suite (encoding.md 4.0.1).
pattern: ^ak:blob:(?:sha256|blake3):[0-9a-f]{64}$
* ratchet_tree_ref · string
Copied byte-for-byte from the accepted ak.mls.genesis payload; the embedded Blob digest suite is the sole wire carrier of the material digest and is independent of the fixed SHA-256 Event/RealmCommit identity suite (encoding.md 4.0.1).
pattern: ^ak:blob:(?:sha256|blake3):[0-9a-f]{64}$
max_response_bytes · integer
example: 8388608
anyOf · anyOf[37] · object · $ref #/$defs/ModerationReportOutcome
* report_id · string
pattern: ^ak:report:[A-Za-z0-9_-]{44}$
routed_to_ids · array<$ref ./common-ids.schema.json#/$defs/did_core_id>
Stable core_ids selected as moderation routing destinations. MUST be omitted for an ordinary reporter and MAY be serialized only when the caller independently holds moderation/governance capability for the report's exact scope. Endpoint discovery and DID verification remain separate resolution steps.
items · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
anyOf · anyOf[38] · object · $ref #/$defs/OrganizationRegistrationChallenge
Single-use control challenge. Every binding field exists to close one replay path: purpose separates this proof from any other signature the organization makes, audience and trust_domain pin it to this deployment, origin pins the HTTP surface, nonce makes it unrepeatable, and the expiry window bounds how long a captured proof stays useful. A registry MUST consume the challenge on the first successful use and atomically persist (challenge_id, canonical_request_digest, outcome). Only a byte-identical retry may return that stored outcome; the same challenge with any different digest is invalid.
* challenge_id · string
pattern: ^ak:organization_registration_challenge:[0-9a-f]{64}$
* organization_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* organization_did · string · $ref ./common-ids.schema.json#/$defs/did
Canonical bare DID used for registration, DID method resolution and owner-published current resolution. It contains no path, query or fragment and MUST project through the registered method adapter to exactly one did_core_id.
pattern: ^did:[a-z0-9]+:[^\s/?#]+$
* purpose · const "ak.organization_registration_control_proof.v1"
Fixed purpose tag, identical to the signing context of OrganizationControlProof.proofs[]. A proof produced for any other purpose MUST NOT verify here.
enum: "ak.organization_registration_control_proof.v1"
* nonce · string
pattern: ^[A-Za-z0-9_-]{22,128}$
* audience_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* origin · string (uri) · format=uri · $ref ./common-ids.schema.json#/$defs/web_origin
Canonical HTTP(S) Web Origin: lowercase scheme/host plus an optional valid non-default effective port. Userinfo, path (including a trailing slash), query, fragment, explicit :80 on HTTP, and explicit :443 on HTTPS are forbidden.
pattern: ^(?:http://(?:\[[0-9A-Fa-f:.]+\]|[a-z0-9](?:[a-z0-9.-]*[a-z0-9])?)(?::(?!80$)(?:[1-9]|[1-9][0-9]{1,3}|[1-5][0-9]{4}|6[0-4][0-9]{3}|65[0-4][0-9]{2}|655[0-2][0-9]|6553[0-5]))?|https://(?:\[[0-9A-Fa-f:.]+\]|[a-z0-9](?:[a-z0-9.-]*[a-z0-9])?)(?::(?!443$)(?:[1-9]|[1-9][0-9]{1,3}|[1-5][0-9]{4}|6[0-4][0-9]{3}|65[0-4][0-9]{2}|655[0-2][0-9]|6553[0-5]))?)$
* trust_domain · string · $ref ./common-ids.schema.json#/$defs/trust_domain
pattern: ^ak:trust_domain:[a-z0-9][a-z0-9._\-:]{0,127}$
* local_admin_subject_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* requested_scopes · array<$ref #/$defs/OrganizationRegistrationScope>
items · string (enum) · $ref #/$defs/OrganizationRegistrationScope
Closed set of local administrative scopes a registration may delegate. organization_profile_manage covers this deployment's local organization profile and display; organization_realm_endorse permits issuing ak.realm.organization statements on the organization's behalf; organization_service_delegate permits declaring organization-to-service delegations locally. The set is closed because an open scope vocabulary would let a deployment mint authority the organization never consented to. Holding a scope is a permission to act later, not an action: registration by itself creates no Realm, membership, governance-Station authority, capability or service delegation.
enum: "organization_profile_manage" "organization_realm_endorse" "organization_service_delegate"
* expires_at · string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
* created_at · string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
anyOf · anyOf[39] · object · $ref #/$defs/OrganizationRegistrationChallengeRequestBody
Request a single-use control challenge for an external Organization DID. Two phases are mandatory: the registry issues the challenge and remembers it, then the caller proves control against it. Folding this into ensure would let the caller supply its own challenge, at which point neither freshness nor single use can be established by the receiver.
* organization_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* organization_did · string · $ref ./common-ids.schema.json#/$defs/did
Canonical bare DID used for registration, DID method resolution and owner-published current resolution. It contains no path, query or fragment and MUST project through the registered method adapter to exactly one did_core_id.
pattern: ^did:[a-z0-9]+:[^\s/?#]+$
* local_admin_subject_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* requested_scopes · array<$ref #/$defs/OrganizationRegistrationScope>
items · string (enum) · $ref #/$defs/OrganizationRegistrationScope
Closed set of local administrative scopes a registration may delegate. organization_profile_manage covers this deployment's local organization profile and display; organization_realm_endorse permits issuing ak.realm.organization statements on the organization's behalf; organization_service_delegate permits declaring organization-to-service delegations locally. The set is closed because an open scope vocabulary would let a deployment mint authority the organization never consented to. Holding a scope is a permission to act later, not an action: registration by itself creates no Realm, membership, governance-Station authority, capability or service delegation.
enum: "organization_profile_manage" "organization_realm_endorse" "organization_service_delegate"
anyOf · anyOf[40] · object · $ref #/$defs/OrganizationRegistrationEnsureRequestBody
Register an external Organization identity with this deployment by submitting both its stable organization_id core and current published organization_did. Idempotent on organization_id: replaying the same registration returns the existing binding with created=false. This operation registers a reference and a local administrative binding; it does not host the DID's method history, does not make this deployment its controller, and does not create Realm state.
* organization_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* organization_did · string · $ref ./common-ids.schema.json#/$defs/did
Canonical bare DID used for registration, DID method resolution and owner-published current resolution. It contains no path, query or fragment and MUST project through the registered method adapter to exactly one did_core_id.
pattern: ^did:[a-z0-9]+:[^\s/?#]+$
* challenge_id · string
pattern: ^ak:organization_registration_challenge:[0-9a-f]{64}$
* version_id · string
The exact resolved DID version the control proof was made against. Pinning the version is what makes the receipt auditable later: without it, a receipt asserts control at an unknown point in the DID's history.
pattern: ^(?!ak:)
* log_head_digest · string
pattern: ^sha256:[0-9a-f]{64}$
* control_proof · object · $ref #/$defs/OrganizationControlProof
Method-native proof that the caller controls the external Organization DID at the pinned version. proof_kind is a closed discriminator with exactly two members, both of which describe a MATURE, already-published DID. Creating a new Organization DID is a separate inception / governance ceremony and deliberately has no member here: a receiver must never have to guess whether a proof asserts control of existing state or creation of new state. This object never carries an Arkret-issued challenge signature in place of method-native control evidence.
allOf · allOf[0] · ?
* proof_kind · string (enum)
resolved_verification_method: a single signature by a verification method that is in the organization DID's control relationship at version_id. governance_quorum: a threshold of signatures from the organization's governance key set. Witness attestation is neither of these and MUST NOT be substituted for control evidence (identity-did.md §8.1).
enum: "resolved_verification_method" "governance_quorum"
quorum_threshold · integer
Required when proof_kind=governance_quorum and forbidden otherwise. The number of distinct valid governance signatures the organization's own policy demands. proofs[] MUST contain at least this many entries signed by distinct verification methods; JSON Schema cannot compare the two, so the receiver MUST enforce it and fail closed when short.
* proofs · array<$ref ./event-envelope.schema.json#/$defs/proof>
Detached proofs over canonical_json({context:'ak.organization_registration_control_proof.v1', challenge_id, organization_id, organization_did, local_admin_subject, version_id, log_head_digest, verification_method, created_at}). The verifier independently validates the published organization_did and requires project(organization_did)=organization_id before checking the DID URL verification_method. Binding the challenge, stable core, DID, beneficiary admin and exact version together prevents replay across deployments, resolutions or beneficiaries.
items · object · $ref ./event-envelope.schema.json#/$defs/proof
Generic detached-JWS proof shape reused by non-Event schemas (snapshot signature, snapshot witness attestations, identity receipts, handle claims, etc.). MUST NOT be used as the shape of Event Envelope `producer_proof` — Event proofs reference $defs/event_proof and bind canonical Event bytes via `event_digest`. Non-Event signed objects MUST define an object-family signing-context constant and include it in the canonical proof binding object with payload_digest; the context constant is not a wire field in this generic shape. drift detection: `payload_digest#event_proof` in forbidden-wire-fields.json is the hard-reject mirror of this rule. New non-Event signed objects MAY $ref this shape; new signed Event-shaped objects MUST instead $ref event_proof.
* kind · string (enum)
Generic detached JWS proof over a canonical non-Event payload binding object that includes an object-family context constant.
enum: "detached_jws"
* verification_method · string
DID URL of the signing key for this non-Event detached proof. Same pattern as $defs/event_proof.verification_method; semantics are decoupled from Event proof (see $defs/event_proof for the Event-only shape).
pattern: ^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$
* payload_digest · $ref #/$defs/digest · $ref #/$defs/digest
Generic non-Event detached-proof hash. This $defs/proof shape is reused by non-Event schemas; Event.properties.producer_proof references $defs/event_proof and MUST use event_digest instead.
* created_at · $ref #/$defs/timestamp · $ref #/$defs/timestamp
domain · string
audience · oneOf[2]
oneOf · oneOf[0] · string
oneOf · oneOf[1] · array<string>
items · string
proof_purpose · string (enum)
Optional role discriminator for non-Event proofs. HandleClaim core, status and revocation carriers make issuer_attestation, holder_acceptance, status_attestation and revocation_authorization load-bearing. governance_authorization marks a resource-governance-key authorization (directory withdraw/takedown-appeal, discovery-directory.md 8.7.1). Generic proof consumers ignore it unless their object-family contract makes it load-bearing.
enum: "issuer_attestation" "holder_acceptance" "status_attestation" "revocation_authorization" "governance_authorization"
* jws · string
pattern: ^[A-Za-z0-9_-]+\.\.[A-Za-z0-9_-]+$
* local_admin_subject_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* requested_scopes · array<$ref #/$defs/OrganizationRegistrationScope>
MUST be identical to the set carried by the referenced challenge; a mismatch means the proof was made for different authority than is being claimed.
items · string (enum) · $ref #/$defs/OrganizationRegistrationScope
Closed set of local administrative scopes a registration may delegate. organization_profile_manage covers this deployment's local organization profile and display; organization_realm_endorse permits issuing ak.realm.organization statements on the organization's behalf; organization_service_delegate permits declaring organization-to-service delegations locally. The set is closed because an open scope vocabulary would let a deployment mint authority the organization never consented to. Holding a scope is a permission to act later, not an action: registration by itself creates no Realm, membership, governance-Station authority, capability or service delegation.
enum: "organization_profile_manage" "organization_realm_endorse" "organization_service_delegate"
handle_attestation · object
Optional supporting attestation only. An organization handle or domain claim may improve discovery and display, but MUST NOT substitute for DID control or quorum proof: whoever operates a domain is not thereby the controller of the organization's DID. Named attestation rather than evidence because it carries exactly one material family (common-fields.md R6).
* subject_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* handle · string
* issuer_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* audience · string
* status · string (enum)
The issuer's assertion at signing time. It is a floor, not a guarantee: a receiver MUST still consult the issuer's current revocation state before relying on the handle for display, because a self-asserted active is exactly what a revoked attestation would also carry.
enum: "active" "revoked"
* expires_at · string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
anyOf · anyOf[41] · object · $ref #/$defs/OrganizationRegistrationOutcome
Result of every organization registration command and of the read surface. Identity, DID, generation and version are read from the signed registration_receipt. created is true exactly on a call that opened a new generation.
* registration_receipt · object · $ref #/$defs/OrganizationRegistrationReceipt
Provider-signed record that this deployment accepted an external Organization DID binding. receipt_claims is exactly the object formed by removing registration_receipt_id and proof from the receipt; registration_receipt_id is ak:organization_registration_receipt:<lowercase hex SHA-256(canonical_json(receipt_claims))>. proof.payload_digest hashes the complete receipt after registration_receipt_id is inserted and proof is removed, so neither digest is self-referential. proof is a detached JWS over the ak.organization_registration_receipt_proof.v1 binding object. The receipt proves acceptance of one generation of one local binding and nothing else: it is not a Realm capability, not membership, not a governance-Station designation, and not a service delegation.
* registration_receipt_id · string
ak:organization_registration_receipt: plus lowercase hex SHA-256(canonical_json(receipt with registration_receipt_id and proof both omitted)).
pattern: ^ak:organization_registration_receipt:[0-9a-f]{64}$
* organization_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* organization_did · string · $ref ./common-ids.schema.json#/$defs/did
Canonical bare DID used for registration, DID method resolution and owner-published current resolution. It contains no path, query or fragment and MUST project through the registered method adapter to exactly one did_core_id.
pattern: ^did:[a-z0-9]+:[^\s/?#]+$
* registration_generation · integer
Monotonic generation of the binding for this stable organization did_core_id, starting at 1. A same-core did refresh does not create a different organization identity; terminal registration states remain per generation.
* version_id · string
pattern: ^(?!ak:)
* log_head_digest · string
pattern: ^sha256:[0-9a-f]{64}$
* control_proof_kind · string (enum)
Mirrors OrganizationControlProof.proof_kind so a later auditor can tell which commitment control_key_digest is over without re-fetching the original request.
enum: "resolved_verification_method" "governance_quorum"
* control_key_digest · string
Under resolved_verification_method, the digest of the active control/update public key at version_id. Under governance_quorum, the digest of the canonical governance key set head that satisfied the threshold. It is never a next-key commitment and never private material.
pattern: ^sha256:[0-9a-f]{64}$
* local_admin_subject_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* delegated_scopes · array<$ref #/$defs/OrganizationRegistrationScope>
items · string (enum) · $ref #/$defs/OrganizationRegistrationScope
Closed set of local administrative scopes a registration may delegate. organization_profile_manage covers this deployment's local organization profile and display; organization_realm_endorse permits issuing ak.realm.organization statements on the organization's behalf; organization_service_delegate permits declaring organization-to-service delegations locally. The set is closed because an open scope vocabulary would let a deployment mint authority the organization never consented to. Holding a scope is a permission to act later, not an action: registration by itself creates no Realm, membership, governance-Station authority, capability or service delegation.
enum: "organization_profile_manage" "organization_realm_endorse" "organization_service_delegate"
* status · string (enum)
Closed lifecycle. active: control evidence is current. stale: the pinned version no longer reflects current control (controller rotation) or the evidence has aged out; low-risk reads may continue but high-risk paths MUST fail closed until a successful refresh. revoked: terminal for this generation, whether withdrawn locally, atomically superseded by a new generation, or forced by deactivation of the external DID. A signed historical receipt can retain status=active as an immutable audit artifact, but it authorizes only while its generation is the registry current generation and that registry state is active.
enum: "active" "stale" "revoked"
* issued_at · string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
* expires_at · string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
* issuer_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* proof · object · $ref ./event-envelope.schema.json#/$defs/proof
Generic detached-JWS proof shape reused by non-Event schemas (snapshot signature, snapshot witness attestations, identity receipts, handle claims, etc.). MUST NOT be used as the shape of Event Envelope `producer_proof` — Event proofs reference $defs/event_proof and bind canonical Event bytes via `event_digest`. Non-Event signed objects MUST define an object-family signing-context constant and include it in the canonical proof binding object with payload_digest; the context constant is not a wire field in this generic shape. drift detection: `payload_digest#event_proof` in forbidden-wire-fields.json is the hard-reject mirror of this rule. New non-Event signed objects MAY $ref this shape; new signed Event-shaped objects MUST instead $ref event_proof.
* kind · string (enum)
Generic detached JWS proof over a canonical non-Event payload binding object that includes an object-family context constant.
enum: "detached_jws"
* verification_method · string
DID URL of the signing key for this non-Event detached proof. Same pattern as $defs/event_proof.verification_method; semantics are decoupled from Event proof (see $defs/event_proof for the Event-only shape).
pattern: ^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$
* payload_digest · $ref #/$defs/digest · $ref #/$defs/digest
Generic non-Event detached-proof hash. This $defs/proof shape is reused by non-Event schemas; Event.properties.producer_proof references $defs/event_proof and MUST use event_digest instead.
* created_at · $ref #/$defs/timestamp · $ref #/$defs/timestamp
domain · string
audience · oneOf[2]
oneOf · oneOf[0] · string
oneOf · oneOf[1] · array<string>
items · string
proof_purpose · string (enum)
Optional role discriminator for non-Event proofs. HandleClaim core, status and revocation carriers make issuer_attestation, holder_acceptance, status_attestation and revocation_authorization load-bearing. governance_authorization marks a resource-governance-key authorization (directory withdraw/takedown-appeal, discovery-directory.md 8.7.1). Generic proof consumers ignore it unless their object-family contract makes it load-bearing.
enum: "issuer_attestation" "holder_acceptance" "status_attestation" "revocation_authorization" "governance_authorization"
* jws · string
pattern: ^[A-Za-z0-9_-]+\.\.[A-Za-z0-9_-]+$
* created · boolean
True exactly when this call opened a new generation: the first registration, a re-registration after revoke, or an ensure that changed local_admin_subject or the scope set. False for a byte-identical ensure retry that matches the consumed challenge's canonical_request_digest and stored outcome, and for every read, refresh and revoke. Reusing the challenge with a different digest is an error, not created=false.
anyOf · anyOf[42] · object · $ref #/$defs/OrganizationRegistrationRefreshRequestBody
Re-prove control at a newer resolved version and re-issue the receipt. Scopes are not re-negotiated here; a scope change is a new ensure. Refresh exists because a binding pinned to one version stops proving current control the moment the organization rotates its controller.
* organization_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* organization_did · string · $ref ./common-ids.schema.json#/$defs/did
Canonical bare DID used for registration, DID method resolution and owner-published current resolution. It contains no path, query or fragment and MUST project through the registered method adapter to exactly one did_core_id.
pattern: ^did:[a-z0-9]+:[^\s/?#]+$
* challenge_id · string
pattern: ^ak:organization_registration_challenge:[0-9a-f]{64}$
* version_id · string
pattern: ^(?!ak:)
* log_head_digest · string
pattern: ^sha256:[0-9a-f]{64}$
* control_proof · object · $ref #/$defs/OrganizationControlProof
Method-native proof that the caller controls the external Organization DID at the pinned version. proof_kind is a closed discriminator with exactly two members, both of which describe a MATURE, already-published DID. Creating a new Organization DID is a separate inception / governance ceremony and deliberately has no member here: a receiver must never have to guess whether a proof asserts control of existing state or creation of new state. This object never carries an Arkret-issued challenge signature in place of method-native control evidence.
allOf · allOf[0] · ?
* proof_kind · string (enum)
resolved_verification_method: a single signature by a verification method that is in the organization DID's control relationship at version_id. governance_quorum: a threshold of signatures from the organization's governance key set. Witness attestation is neither of these and MUST NOT be substituted for control evidence (identity-did.md §8.1).
enum: "resolved_verification_method" "governance_quorum"
quorum_threshold · integer
Required when proof_kind=governance_quorum and forbidden otherwise. The number of distinct valid governance signatures the organization's own policy demands. proofs[] MUST contain at least this many entries signed by distinct verification methods; JSON Schema cannot compare the two, so the receiver MUST enforce it and fail closed when short.
* proofs · array<$ref ./event-envelope.schema.json#/$defs/proof>
Detached proofs over canonical_json({context:'ak.organization_registration_control_proof.v1', challenge_id, organization_id, organization_did, local_admin_subject, version_id, log_head_digest, verification_method, created_at}). The verifier independently validates the published organization_did and requires project(organization_did)=organization_id before checking the DID URL verification_method. Binding the challenge, stable core, DID, beneficiary admin and exact version together prevents replay across deployments, resolutions or beneficiaries.
items · object · $ref ./event-envelope.schema.json#/$defs/proof
Generic detached-JWS proof shape reused by non-Event schemas (snapshot signature, snapshot witness attestations, identity receipts, handle claims, etc.). MUST NOT be used as the shape of Event Envelope `producer_proof` — Event proofs reference $defs/event_proof and bind canonical Event bytes via `event_digest`. Non-Event signed objects MUST define an object-family signing-context constant and include it in the canonical proof binding object with payload_digest; the context constant is not a wire field in this generic shape. drift detection: `payload_digest#event_proof` in forbidden-wire-fields.json is the hard-reject mirror of this rule. New non-Event signed objects MAY $ref this shape; new signed Event-shaped objects MUST instead $ref event_proof.
* kind · string (enum)
Generic detached JWS proof over a canonical non-Event payload binding object that includes an object-family context constant.
enum: "detached_jws"
* verification_method · string
DID URL of the signing key for this non-Event detached proof. Same pattern as $defs/event_proof.verification_method; semantics are decoupled from Event proof (see $defs/event_proof for the Event-only shape).
pattern: ^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$
* payload_digest · $ref #/$defs/digest · $ref #/$defs/digest
Generic non-Event detached-proof hash. This $defs/proof shape is reused by non-Event schemas; Event.properties.producer_proof references $defs/event_proof and MUST use event_digest instead.
* created_at · $ref #/$defs/timestamp · $ref #/$defs/timestamp
domain · string
audience · oneOf[2]
oneOf · oneOf[0] · string
oneOf · oneOf[1] · array<string>
items · string
proof_purpose · string (enum)
Optional role discriminator for non-Event proofs. HandleClaim core, status and revocation carriers make issuer_attestation, holder_acceptance, status_attestation and revocation_authorization load-bearing. governance_authorization marks a resource-governance-key authorization (directory withdraw/takedown-appeal, discovery-directory.md 8.7.1). Generic proof consumers ignore it unless their object-family contract makes it load-bearing.
enum: "issuer_attestation" "holder_acceptance" "status_attestation" "revocation_authorization" "governance_authorization"
* jws · string
pattern: ^[A-Za-z0-9_-]+\.\.[A-Za-z0-9_-]+$
anyOf · anyOf[43] · object · $ref #/$defs/OrganizationRegistrationRevokeRequestBody
Withdraw the local binding. This is a local act with local effect only: it does not modify, deactivate or annotate the external DID's method history, which this deployment does not control.
* organization_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
reason_code · string (enum)
Closed reason set. superseded: replaced by a new binding for the same organization. withdrawn: the deployment or the organization ended the relationship.
enum: "organization_registration_superseded" "organization_registration_withdrawn"
anyOf · anyOf[44] · object · $ref #/$defs/ProjectionMorphList
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* morphs · array<$ref #/$defs/ProjectionMorphRow>
items · object · $ref #/$defs/ProjectionMorphRow
allOf · allOf[0] · ?
* morph_id · string
pattern: ^ak:morph:[A-Za-z0-9_-]{44}$
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* morph_kind · string
title · oneOf[2]
oneOf · oneOf[0] · string (arkret-single-line-display-text) · format=arkret-single-line-display-text · $ref string-profiles.schema.json#/$defs/display_text_512
NFC multilingual single-line display text; mixed scripts, emoji, and symbols are allowed.
pattern: ^[^\u0000-\u001F\u007F-\u009F\u202A-\u202E\u2066-\u2069\uFEFF]*[^\s\u0000-\u001F\u007F-\u009F\u202A-\u202E\u2066-\u2069\uFEFF][^\u0000-\u001F\u007F-\u009F\u202A-\u202E\u2066-\u2069\uFEFF]*$
oneOf · oneOf[1] · null
* state · string (enum)
enum: "active" "archived" "redacted"
state_changed_at · oneOf[2] · $ref ./time.schema.json#/$defs/nullable_timestamp
oneOf · oneOf[0] · $ref #/$defs/timestamp · $ref #/$defs/timestamp
oneOf · oneOf[1] · null
stage · oneOf[2]
Business-progression stage from the domain current result; null or absent when the object has never been written by ak.<kind>.stage.set. Orthogonal to the physical lifecycle in state (common-fields.md 5.3).
oneOf · oneOf[0] · string (enum)
enum: "draft" "proposed" "planned" "in_progress" "blocked" "done" "cancelled" "superseded"
oneOf · oneOf[1] · null
stage_changed_at · oneOf[2] · $ref ./time.schema.json#/$defs/nullable_timestamp
Reducer-derived timestamp of the most recent stage transition; MUST NOT be present without stage (common-fields.md 5.3.1).
oneOf · oneOf[0] · $ref #/$defs/timestamp · $ref #/$defs/timestamp
oneOf · oneOf[1] · null
created_by · oneOf[2]
oneOf · oneOf[0] · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind · const "account"
enum: "account"
* account_id · $ref #/$defs/account_id · $ref #/$defs/account_id
oneOf · oneOf[1] · object
* kind · const "service"
enum: "service"
* service_id · $ref #/$defs/did_core_id · $ref #/$defs/did_core_id
oneOf · oneOf[1] · null
created_at · oneOf[2] · $ref ./time.schema.json#/$defs/nullable_timestamp
oneOf · oneOf[0] · $ref #/$defs/timestamp · $ref #/$defs/timestamp
oneOf · oneOf[1] · null
updated_at · oneOf[2] · $ref ./time.schema.json#/$defs/nullable_timestamp
oneOf · oneOf[0] · $ref #/$defs/timestamp · $ref #/$defs/timestamp
oneOf · oneOf[1] · null
* total · integer
next_cursor · string
pattern: ^ak:cursor:[A-Za-z0-9_-]+$
* has_more · boolean
anyOf · anyOf[45] · object · $ref #/$defs/ProjectionSpaceList
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* spaces · array<$ref #/$defs/ProjectionSpaceRow>
items · object · $ref #/$defs/ProjectionSpaceRow
oneOf · oneOf[0] · ?
oneOf · oneOf[1] · ?
* space_id · string
pattern: ^ak:space:[A-Za-z0-9_-]{44}$
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* kind · string
Space kind such as `board`, `list`, `folder`, or a profile-registered kind.
title · string (arkret-single-line-display-text) · format=arkret-single-line-display-text · $ref string-profiles.schema.json#/$defs/display_text_256
NFC multilingual single-line display text; mixed scripts, emoji, and symbols are allowed.
pattern: ^[^\u0000-\u001F\u007F-\u009F\u202A-\u202E\u2066-\u2069\uFEFF]*[^\s\u0000-\u001F\u007F-\u009F\u202A-\u202E\u2066-\u2069\uFEFF][^\u0000-\u001F\u007F-\u009F\u202A-\u202E\u2066-\u2069\uFEFF]*$
encrypted_metadata · object · $ref ./encrypted-envelope.schema.json
Minimal ciphertext wire. purpose, effective scope and Event kind come from the frozen signed outer Event; mls_group_id is derived from that scope. The canonical pre-encryption header is reconstructed and is not duplicated on wire.
* version · const "1.0"
enum: "1.0"
* content_type · string
pattern: ^[a-z0-9.+-]+/[a-z0-9.+-]+$
* encryption_context · $ref #/$defs/encryption_context · $ref #/$defs/encryption_context
* ciphertext · string
pattern: ^[A-Za-z0-9_-]+$
parent_space_id · string | null
rank · string | null
* state · string (enum)
enum: "active" "archived" "tombstoned"
state_changed_at · oneOf[2] · $ref ./time.schema.json#/$defs/nullable_timestamp
oneOf · oneOf[0] · $ref #/$defs/timestamp · $ref #/$defs/timestamp
oneOf · oneOf[1] · null
created_by · oneOf[2]
oneOf · oneOf[0] · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind · const "account"
enum: "account"
* account_id · $ref #/$defs/account_id · $ref #/$defs/account_id
oneOf · oneOf[1] · object
* kind · const "service"
enum: "service"
* service_id · $ref #/$defs/did_core_id · $ref #/$defs/did_core_id
oneOf · oneOf[1] · null
created_at · oneOf[2] · $ref ./time.schema.json#/$defs/nullable_timestamp
oneOf · oneOf[0] · $ref #/$defs/timestamp · $ref #/$defs/timestamp
oneOf · oneOf[1] · null
updated_at · oneOf[2] · $ref ./time.schema.json#/$defs/nullable_timestamp
oneOf · oneOf[0] · $ref #/$defs/timestamp · $ref #/$defs/timestamp
oneOf · oneOf[1] · null
* total · integer
next_cursor · string
pattern: ^ak:cursor:[A-Za-z0-9_-]+$
* has_more · boolean
anyOf · anyOf[46] · object · $ref #/$defs/ProjectionStrandList
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* strands · array<$ref #/$defs/ProjectionStrandRow>
items · object · $ref #/$defs/ProjectionStrandRow
allOf · allOf[0] · ?
* strand_id · string
pattern: ^ak:strand:[A-Za-z0-9_-]{44}$
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* state · string (enum)
enum: "active" "archived" "redacted"
state_changed_at · oneOf[2] · $ref ./time.schema.json#/$defs/nullable_timestamp
oneOf · oneOf[0] · $ref #/$defs/timestamp · $ref #/$defs/timestamp
oneOf · oneOf[1] · null
stage · oneOf[2]
Business-progression stage from the domain current result; null or absent when the object has never been written by ak.<kind>.stage.set. Orthogonal to the physical lifecycle in state (common-fields.md 5.3).
oneOf · oneOf[0] · string (enum)
enum: "draft" "proposed" "planned" "in_progress" "blocked" "done" "cancelled" "superseded"
oneOf · oneOf[1] · null
stage_changed_at · oneOf[2] · $ref ./time.schema.json#/$defs/nullable_timestamp
Reducer-derived timestamp of the most recent stage transition; MUST NOT be present without stage (common-fields.md 5.3.1).
oneOf · oneOf[0] · $ref #/$defs/timestamp · $ref #/$defs/timestamp
oneOf · oneOf[1] · null
title · oneOf[2]
Derived display title from plaintext-visible Strand metadata.title; null when metadata is encrypted or hidden from the service profile.
oneOf · oneOf[0] · string (arkret-single-line-display-text) · format=arkret-single-line-display-text · $ref string-profiles.schema.json#/$defs/display_text_512
NFC multilingual single-line display text; mixed scripts, emoji, and symbols are allowed.
pattern: ^[^\u0000-\u001F\u007F-\u009F\u202A-\u202E\u2066-\u2069\uFEFF]*[^\s\u0000-\u001F\u007F-\u009F\u202A-\u202E\u2066-\u2069\uFEFF][^\u0000-\u001F\u007F-\u009F\u202A-\u202E\u2066-\u2069\uFEFF]*$
oneOf · oneOf[1] · null
summary · oneOf[2]
Derived display summary from plaintext-visible Strand metadata.summary; null when metadata is encrypted or hidden from the service profile.
oneOf · oneOf[0] · string (arkret-short-text) · format=arkret-short-text · $ref string-profiles.schema.json#/$defs/short_text
NFC multilingual short text. LF is allowed; CR, other C0/C1 controls, BOM, and bidi embedding/override controls are rejected.
pattern: ^[^\u0000-\u0009\u000B-\u001F\u007F-\u009F\u202A-\u202E\uFEFF]*$
oneOf · oneOf[1] · null
topic · object · $ref ./strand.schema.json#/$defs/strand_topic
* space_id · string
pattern: ^ak:space:[A-Za-z0-9_-]{44}$
* rank · string
pattern: ^[A-Za-z0-9]{1,128}$
board_space_id · string | null
Derived board Space id from strand_position; not canonical Strand object state.
pattern: ^ak:space:[A-Za-z0-9_-]{44}$
list_space_id · string | null
Derived list Space id from strand_position; not canonical Strand object state.
pattern: ^ak:space:[A-Za-z0-9_-]{44}$
rank · string | null
Derived rank within list_space_id from strand_position.
assigned_actor_ids · array<$ref ./common-ids.schema.json#/$defs/actor_id>
Derived current full ActorIds from visible active Relation(relation_kind=assigned_to, from_ref=strand_id), preserving Station identity. Empty or absent means the Strand is unassigned for this projection caller. This is read-model state, not canonical Strand object metadata.
items · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind · const "account"
enum: "account"
* account_id · $ref #/$defs/account_id · $ref #/$defs/account_id
oneOf · oneOf[1] · object
* kind · const "service"
enum: "service"
* service_id · $ref #/$defs/did_core_id · $ref #/$defs/did_core_id
assigned_to_relations · array<$ref #/$defs/ProjectionAssignedToRelation>
Read-only active assigned_to Relation edges backing assigned_actor_ids. Clients use relation_id to tombstone assignments.
items · object · $ref #/$defs/ProjectionAssignedToRelation
Read-model edge backing a Strand assigned_to Relation. relation_id is needed by clients to tombstone the assignment; actor_id mirrors the Relation to_ref.
* relation_id · string
pattern: ^ak:relation:[A-Za-z0-9_-]{44}$
* actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind · const "account"
enum: "account"
* account_id · $ref #/$defs/account_id · $ref #/$defs/account_id
oneOf · oneOf[1] · object
* kind · const "service"
enum: "service"
* service_id · $ref #/$defs/did_core_id · $ref #/$defs/did_core_id
created_by · oneOf[2]
oneOf · oneOf[0] · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind · const "account"
enum: "account"
* account_id · $ref #/$defs/account_id · $ref #/$defs/account_id
oneOf · oneOf[1] · object
* kind · const "service"
enum: "service"
* service_id · $ref #/$defs/did_core_id · $ref #/$defs/did_core_id
oneOf · oneOf[1] · null
created_at · oneOf[2] · $ref ./time.schema.json#/$defs/nullable_timestamp
oneOf · oneOf[0] · $ref #/$defs/timestamp · $ref #/$defs/timestamp
oneOf · oneOf[1] · null
updated_by · oneOf[2]
oneOf · oneOf[0] · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind · const "account"
enum: "account"
* account_id · $ref #/$defs/account_id · $ref #/$defs/account_id
oneOf · oneOf[1] · object
* kind · const "service"
enum: "service"
* service_id · $ref #/$defs/did_core_id · $ref #/$defs/did_core_id
oneOf · oneOf[1] · null
updated_at · oneOf[2] · $ref ./time.schema.json#/$defs/nullable_timestamp
oneOf · oneOf[0] · $ref #/$defs/timestamp · $ref #/$defs/timestamp
oneOf · oneOf[1] · null
* is_default · boolean
DERIVED, not independent storage: true iff strand_id == the parent Realm projection's default_strand_id (the authoritative pointer written by ak.realm.set_default_strand). The projector computes this from Realm.default_strand_id; a stale/dangling pointer never resolves to is_default=true because the reducer rejects set_default_strand against a non-existent Strand. Clients identify the Realm's default discussion Strand deterministically from this flag (or equivalently from Realm.default_strand_id) and MUST NOT infer the default from any Strand-reuses-Realm-token or other implementation detail. See zh/models/strand-and-message.md (default-Strand discovery).
* total · integer
next_cursor · string
pattern: ^ak:cursor:[A-Za-z0-9_-]+$
* has_more · boolean
anyOf · anyOf[47] · object · $ref #/$defs/StrandWatchCurrentRequestBody
Exact self watch selector. It cannot enumerate watchers or supply an expected CAS value.
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* strand_id · string · $ref ./event-payload.schema.json#/$defs/strand_id
pattern: ^ak:strand:[A-Za-z0-9_-]{44}$
* watcher_actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind · const "account"
enum: "account"
* account_id · $ref #/$defs/account_id · $ref #/$defs/account_id
oneOf · oneOf[1] · object
* kind · const "service"
enum: "service"
* service_id · $ref #/$defs/did_core_id · $ref #/$defs/did_core_id
anyOf · anyOf[48] · oneOf[2] · $ref #/$defs/StrandWatchCurrentOutcome
A verified never-written fact is distinct from a written result whose value was cleared to null.
oneOf · oneOf[0] · object · $ref #/$defs/StrandWatchCurrentNeverWritten
* status · const "never_written"
enum: "never_written"
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* governance_generation · integer
* stream_head · object · $ref ./realm-commit.schema.json#/$defs/stream_head
* stream_ref · $ref #/$defs/stream_ref · $ref #/$defs/stream_ref
* stream_position · integer
* commit_id · string · $ref ./common-ids.schema.json#/$defs/realm_commit_id
Content-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern: ^ak:realm_commit:[A-Za-z0-9_-]{44}$
* selector · object · $ref ./typed-current-result.schema.json#/$defs/strand_watch_result/properties/selector
* kind · const "strand_watch"
enum: "strand_watch"
* strand_id · string · $ref ./event-payload.schema.json#/$defs/strand_id
pattern: ^ak:strand:[A-Za-z0-9_-]{44}$
* watcher_actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind · const "account"
enum: "account"
* account_id · $ref #/$defs/account_id · $ref #/$defs/account_id
oneOf · oneOf[1] · object
* kind · const "service"
enum: "service"
* service_id · $ref #/$defs/did_core_id · $ref #/$defs/did_core_id
oneOf · oneOf[1] · object · $ref #/$defs/StrandWatchCurrentPresent
* status · const "current"
enum: "current"
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* governance_generation · integer
* stream_head · object · $ref ./realm-commit.schema.json#/$defs/stream_head
* stream_ref · $ref #/$defs/stream_ref · $ref #/$defs/stream_ref
* stream_position · integer
* commit_id · string · $ref ./common-ids.schema.json#/$defs/realm_commit_id
Content-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern: ^ak:realm_commit:[A-Za-z0-9_-]{44}$
* result · object · $ref ./typed-current-result.schema.json#/$defs/strand_watch_result
* selector · object
* kind · const "strand_watch"
enum: "strand_watch"
* strand_id · string · $ref ./event-payload.schema.json#/$defs/strand_id
pattern: ^ak:strand:[A-Za-z0-9_-]{44}$
* watcher_actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind · const "account"
enum: "account"
* account_id · $ref #/$defs/account_id · $ref #/$defs/account_id
oneOf · oneOf[1] · object
* kind · const "service"
enum: "service"
* service_id · $ref #/$defs/did_core_id · $ref #/$defs/did_core_id
* source_stream_ref · oneOf[3] · $ref ./realm-commit.schema.json#/$defs/stream_ref
Closed visibility-stream selector. Realm, each Circle and each Sidecar have independent continuous positions so hidden scopes do not leak through global gaps.
oneOf · oneOf[0] · object
* kind · const "realm"
enum: "realm"
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
oneOf · oneOf[1] · object
* kind · const "circle"
enum: "circle"
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* circle_id · string · $ref ./common-ids.schema.json#/$defs/circle_id
pattern: ^ak:circle:[A-Za-z0-9_-]{44}$
oneOf · oneOf[2] · object
* kind · const "sidecar"
enum: "sidecar"
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* sidecar_id · string · $ref ./common-ids.schema.json#/$defs/sidecar_id
pattern: ^ak:sidecar:[A-Za-z0-9_-]{44}$
* revision · $ref #/$defs/revision · $ref #/$defs/revision
* value · $ref #/$defs/strand_watch_value · $ref #/$defs/strand_watch_value
anyOf · anyOf[49] · object · $ref #/$defs/ServiceRegistrationEnsureRequestBody
* service_kind · string (enum) · $ref #/$defs/ServiceRegistrationKey/properties/service_kind
enum: "station" "identity_registry"
* public_base_url · string (uri) · format=uri · $ref #/$defs/ServiceRegistrationKey/properties/public_base_url
Canonical service base URL: lower-case scheme and host, no query or fragment, normalized path, and exactly one trailing slash. Production deployments MUST use https; explicit development deployments MAY use http.
pattern: ^https?://[^?#]+/$
* did · string · $ref ./common-ids.schema.json#/$defs/did
Canonical bare DID used for registration, DID method resolution and owner-published current resolution. It contains no path, query or fragment and MUST project through the registered method adapter to exactly one did_core_id.
pattern: ^did:[a-z0-9]+:[^\s/?#]+$
* inception_operation · object · $ref #/$defs/ServiceWebvhInceptionOperation
* versionId · string
pattern: ^1-[1-9A-HJ-NP-Za-km-z]+$
* versionTime · string (date-time) · format=date-time
* parameters · object · $ref #/$defs/ServiceWebvhInceptionParameters
* scid · string
pattern: ^[1-9A-HJ-NP-Za-km-z]+$
* method · const "did:webvh:1.0"
enum: "did:webvh:1.0"
* updateKeys · array<string>
Exactly one active service-controlled update key. On a rotation entry it MUST open the previous entry's sole nextKeyHashes commitment; spent keys MUST NOT be reused.
items · string
pattern: ^z[1-9A-HJ-NP-Za-km-z]+$
* nextKeyHashes · array<string>
Exactly one sha2-256 multihash/Base58BTC commitment to a next update key generated and durably held by the service. Missing or mismatched commitments fail closed as service_prerotation_invalid.
items · string
pattern: ^[1-9A-HJ-NP-Za-km-z]+$
* state · object · $ref #/$defs/ServiceDidDocument
* @context · array<string (uri)>
items · string (uri) · format=uri
* id · string · $ref ./common-ids.schema.json#/$defs/webvh_did
Canonical bare did:webvh identifier used at method-native registration, document and evidence boundaries. Role admission is enforced separately.
pattern: ^did:webvh:[^\s:/?#]+:[^\s/?#]+$
alsoKnownAs · array<string (uri)>
items · string (uri) · format=uri
* verificationMethod · array<$ref #/$defs/ServiceDidVerificationMethod>
items · object · $ref #/$defs/ServiceDidVerificationMethod
* id · string
pattern: ^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$
* type · const "Multikey"
enum: "Multikey"
* controller · string · $ref ./common-ids.schema.json#/$defs/did
Canonical bare DID used for registration, DID method resolution and owner-published current resolution. It contains no path, query or fragment and MUST project through the registered method adapter to exactly one did_core_id.
pattern: ^did:[a-z0-9]+:[^\s/?#]+$
* publicKeyMultibase · string
pattern: ^z[1-9A-HJ-NP-Za-km-z]+$
* authentication · array<string>
items · string
pattern: ^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$
* assertionMethod · array<string>
items · string
pattern: ^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$
* service · array<$ref #/$defs/ServiceDidEndpoint>
items · object · $ref #/$defs/ServiceDidEndpoint
* id · string
pattern: ^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$
* type · const "ArkretService"
enum: "ArkretService"
* serviceKind · string (enum)
enum: "station" "identity_registry"
* serviceEndpoint · string (uri) · format=uri
pattern: ^https?://[^?#]+/$
* proof · array<$ref #/$defs/ServiceWebvhDataIntegrityProof>
items · object · $ref #/$defs/ServiceWebvhDataIntegrityProof
* type · const "DataIntegrityProof"
enum: "DataIntegrityProof"
* cryptosuite · const "eddsa-jcs-2022"
enum: "eddsa-jcs-2022"
* verificationMethod · string
pattern: ^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$
* proofPurpose · const "assertionMethod"
enum: "assertionMethod"
* proofValue · string
pattern: ^z[1-9A-HJ-NP-Za-km-z]+$
* idempotency_key · string · $ref ./principal-operations.schema.json#/$defs/opaque_id
Bounded opaque caller-chosen correlation string used only to relate audit records for one ensure attempt. It is deliberately outside the ak: typed-ID namespace and MUST NOT be parsed by the typed-ID parser or treated as an object identity. Registration identity is the canonical (service_kind, public_base_url) key that Provider persistence enforces with UNIQUE(service_kind, public_base_url), and the single idempotency authority for this operation is the operation registry's idempotency_mechanism=object_id; this field never establishes a second one.
previous_receipt · oneOf[2]
oneOf · oneOf[0] · object · $ref #/$defs/ServiceRegistrationReceipt
Provider-signed stable service-registration receipt. registration_receipt_id is ak:service_registration_receipt:<lowercase hex SHA-256(canonical_json(receipt claims))>. service_id is the projected did_core_id and did is the verified DID. proof is a detached JWS over the ak.service_registration_receipt_proof.v1 binding object; consumers verify the provider through its own resolution evidence.
* registration_receipt_id · string
pattern: ^ak:service_registration_receipt:[0-9a-f]{64}$
* registration_key · object · $ref #/$defs/ServiceRegistrationKey
* service_kind · string (enum)
enum: "station" "identity_registry"
* public_base_url · string (uri) · format=uri
Canonical service base URL: lower-case scheme and host, no query or fragment, normalized path, and exactly one trailing slash. Production deployments MUST use https; explicit development deployments MAY use http.
pattern: ^https?://[^?#]+/$
* service_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* did · string · $ref ./common-ids.schema.json#/$defs/did
Canonical bare DID used for registration, DID method resolution and owner-published current resolution. It contains no path, query or fragment and MUST project through the registered method adapter to exactly one did_core_id.
pattern: ^did:[a-z0-9]+:[^\s/?#]+$
* version_id · string
pattern: ^(?!ak:)
* log_head_digest · string
pattern: ^sha256:[0-9a-f]{64}$
* control_key_digest · string
Digest of the active control/update public key at version_id; this is not the next-key commitment or private recovery material.
pattern: ^sha256:[0-9a-f]{64}$
* issued_at · string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
* provider_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* proof · object · $ref ./event-envelope.schema.json#/$defs/proof
Generic detached-JWS proof shape reused by non-Event schemas (snapshot signature, snapshot witness attestations, identity receipts, handle claims, etc.). MUST NOT be used as the shape of Event Envelope `producer_proof` — Event proofs reference $defs/event_proof and bind canonical Event bytes via `event_digest`. Non-Event signed objects MUST define an object-family signing-context constant and include it in the canonical proof binding object with payload_digest; the context constant is not a wire field in this generic shape. drift detection: `payload_digest#event_proof` in forbidden-wire-fields.json is the hard-reject mirror of this rule. New non-Event signed objects MAY $ref this shape; new signed Event-shaped objects MUST instead $ref event_proof.
* kind · string (enum)
Generic detached JWS proof over a canonical non-Event payload binding object that includes an object-family context constant.
enum: "detached_jws"
* verification_method · string
DID URL of the signing key for this non-Event detached proof. Same pattern as $defs/event_proof.verification_method; semantics are decoupled from Event proof (see $defs/event_proof for the Event-only shape).
pattern: ^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$
* payload_digest · $ref #/$defs/digest · $ref #/$defs/digest
Generic non-Event detached-proof hash. This $defs/proof shape is reused by non-Event schemas; Event.properties.producer_proof references $defs/event_proof and MUST use event_digest instead.
* created_at · $ref #/$defs/timestamp · $ref #/$defs/timestamp
domain · string
audience · oneOf[2]
oneOf · oneOf[0] · string
oneOf · oneOf[1] · array<string>
items · string
proof_purpose · string (enum)
Optional role discriminator for non-Event proofs. HandleClaim core, status and revocation carriers make issuer_attestation, holder_acceptance, status_attestation and revocation_authorization load-bearing. governance_authorization marks a resource-governance-key authorization (directory withdraw/takedown-appeal, discovery-directory.md 8.7.1). Generic proof consumers ignore it unless their object-family contract makes it load-bearing.
enum: "issuer_attestation" "holder_acceptance" "status_attestation" "revocation_authorization" "governance_authorization"
* jws · string
pattern: ^[A-Za-z0-9_-]+\.\.[A-Za-z0-9_-]+$
oneOf · oneOf[1] · null
anyOf · anyOf[50] · object · $ref #/$defs/ServiceRegistrationOutcome
* did_document · object · $ref #/$defs/ServiceDidDocument
* @context · array<string (uri)>
items · string (uri) · format=uri
* id · string · $ref ./common-ids.schema.json#/$defs/webvh_did
Canonical bare did:webvh identifier used at method-native registration, document and evidence boundaries. Role admission is enforced separately.
pattern: ^did:webvh:[^\s:/?#]+:[^\s/?#]+$
alsoKnownAs · array<string (uri)>
items · string (uri) · format=uri
* verificationMethod · array<$ref #/$defs/ServiceDidVerificationMethod>
items · object · $ref #/$defs/ServiceDidVerificationMethod
* id · string
pattern: ^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$
* type · const "Multikey"
enum: "Multikey"
* controller · string · $ref ./common-ids.schema.json#/$defs/did
Canonical bare DID used for registration, DID method resolution and owner-published current resolution. It contains no path, query or fragment and MUST project through the registered method adapter to exactly one did_core_id.
pattern: ^did:[a-z0-9]+:[^\s/?#]+$
* publicKeyMultibase · string
pattern: ^z[1-9A-HJ-NP-Za-km-z]+$
* authentication · array<string>
items · string
pattern: ^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$
* assertionMethod · array<string>
items · string
pattern: ^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$
* service · array<$ref #/$defs/ServiceDidEndpoint>
items · object · $ref #/$defs/ServiceDidEndpoint
* id · string
pattern: ^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$
* type · const "ArkretService"
enum: "ArkretService"
* serviceKind · string (enum)
enum: "station" "identity_registry"
* serviceEndpoint · string (uri) · format=uri
pattern: ^https?://[^?#]+/$
* registration_receipt · object · $ref #/$defs/ServiceRegistrationReceipt
Provider-signed stable service-registration receipt. registration_receipt_id is ak:service_registration_receipt:<lowercase hex SHA-256(canonical_json(receipt claims))>. service_id is the projected did_core_id and did is the verified DID. proof is a detached JWS over the ak.service_registration_receipt_proof.v1 binding object; consumers verify the provider through its own resolution evidence.
* registration_receipt_id · string
pattern: ^ak:service_registration_receipt:[0-9a-f]{64}$
* registration_key · object · $ref #/$defs/ServiceRegistrationKey
* service_kind · string (enum)
enum: "station" "identity_registry"
* public_base_url · string (uri) · format=uri
Canonical service base URL: lower-case scheme and host, no query or fragment, normalized path, and exactly one trailing slash. Production deployments MUST use https; explicit development deployments MAY use http.
pattern: ^https?://[^?#]+/$
* service_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* did · string · $ref ./common-ids.schema.json#/$defs/did
Canonical bare DID used for registration, DID method resolution and owner-published current resolution. It contains no path, query or fragment and MUST project through the registered method adapter to exactly one did_core_id.
pattern: ^did:[a-z0-9]+:[^\s/?#]+$
* version_id · string
pattern: ^(?!ak:)
* log_head_digest · string
pattern: ^sha256:[0-9a-f]{64}$
* control_key_digest · string
Digest of the active control/update public key at version_id; this is not the next-key commitment or private recovery material.
pattern: ^sha256:[0-9a-f]{64}$
* issued_at · string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
* provider_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* proof · object · $ref ./event-envelope.schema.json#/$defs/proof
Generic detached-JWS proof shape reused by non-Event schemas (snapshot signature, snapshot witness attestations, identity receipts, handle claims, etc.). MUST NOT be used as the shape of Event Envelope `producer_proof` — Event proofs reference $defs/event_proof and bind canonical Event bytes via `event_digest`. Non-Event signed objects MUST define an object-family signing-context constant and include it in the canonical proof binding object with payload_digest; the context constant is not a wire field in this generic shape. drift detection: `payload_digest#event_proof` in forbidden-wire-fields.json is the hard-reject mirror of this rule. New non-Event signed objects MAY $ref this shape; new signed Event-shaped objects MUST instead $ref event_proof.
* kind · string (enum)
Generic detached JWS proof over a canonical non-Event payload binding object that includes an object-family context constant.
enum: "detached_jws"
* verification_method · string
DID URL of the signing key for this non-Event detached proof. Same pattern as $defs/event_proof.verification_method; semantics are decoupled from Event proof (see $defs/event_proof for the Event-only shape).
pattern: ^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$
* payload_digest · $ref #/$defs/digest · $ref #/$defs/digest
Generic non-Event detached-proof hash. This $defs/proof shape is reused by non-Event schemas; Event.properties.producer_proof references $defs/event_proof and MUST use event_digest instead.
* created_at · $ref #/$defs/timestamp · $ref #/$defs/timestamp
domain · string
audience · oneOf[2]
oneOf · oneOf[0] · string
oneOf · oneOf[1] · array<string>
items · string
proof_purpose · string (enum)
Optional role discriminator for non-Event proofs. HandleClaim core, status and revocation carriers make issuer_attestation, holder_acceptance, status_attestation and revocation_authorization load-bearing. governance_authorization marks a resource-governance-key authorization (directory withdraw/takedown-appeal, discovery-directory.md 8.7.1). Generic proof consumers ignore it unless their object-family contract makes it load-bearing.
enum: "issuer_attestation" "holder_acceptance" "status_attestation" "revocation_authorization" "governance_authorization"
* jws · string
pattern: ^[A-Za-z0-9_-]+\.\.[A-Za-z0-9_-]+$
* created · boolean
anyOf · anyOf[51] · object · $ref #/$defs/SessionGrantIntrospectOutcome
allOf · allOf[0] · ?
* active · boolean
Whether the grant is currently valid for the requested audience. READ-ONLY: introspection never consumes the grant.
* status · string (enum)
enum: "active" "revoked" "superseded" "expired" "locked" "suspended" "audience_mismatch" "proof_required" "invalid_proof" "not_found"
* proof_required · boolean
Whether an additional S2S holder proof is required to confirm the grant active for this introspection request. Default Station grant+DPoP validation uses the request DPoP instead of this field.
* one_time_use_consumed · boolean
Always false: introspection is read-only and never consumes single-use state (rotation is the refresh endpoint's job).
grant · object · $ref #/$defs/SessionGrantIntrospectGrant
Non-secret grant metadata returned to the validating Station. Never includes the grant JWT, refresh token, or session private key.
allOf · allOf[0] · ?
allOf · allOf[1] · ?
allOf · allOf[2] · ?
allOf · allOf[3] · ?
* id · string · $ref ./common-ids.schema.json#/$defs/session_grant_id
pattern: ^ak:session_grant:[A-Za-z0-9_-]{44}$
* issuer_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id · $ref #/$defs/did_core_id · $ref #/$defs/did_core_id
* station_id · $ref #/$defs/did_core_id · $ref #/$defs/did_core_id
device_id · string · $ref ./common-ids.schema.json#/$defs/device_id
pattern: ^ak:device:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$
* audience_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* scopes · array<string>
items · string
* expires_at · string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
revoked_at · string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
* revocation_ref · string
* session_public_key · string
Session signing key (JWK) for RFC 9421 PoP verification on /_arkret/self/* (api-conventions §3.2). Server-to-server only.
* cnf_jkt · string
RFC 7638 JWK SHA-256 thumbprint of the holder (DPoP) key the grant is bound to (cnf.jkt); the Station uses it to verify the per-request DPoP proof on /_arkret/self/* (api-conventions §3.3). Server-to-server only.
* credential_class · string (enum) · $ref #/$defs/SessionGrantCredentialClass
Closed credential class. recovery_session is a <=15 minute, non-refreshable, DPoP-bound candidate-device grant restricted to the exact recovery operation set; recovery completion issues a distinct standard grant.
enum: "standard" "recovery_session"
* holder_binding · oneOf[3] · $ref ./principal-operations.schema.json#/$defs/session_grant_holder_binding
Required closed accepted human-device, recovery candidate-device, or Agent-runtime holder binding.
oneOf · oneOf[0] · object
* kind · const "human_device"
enum: "human_device"
* device_binding · $ref #/$defs/opaque_id · $ref #/$defs/opaque_id
oneOf · oneOf[1] · object
* kind · const "agent_runtime"
enum: "agent_runtime"
* agent_id · $ref #/$defs/did_core_id · $ref #/$defs/did_core_id
* agent_key_authorization_ref · $ref #/$defs/event_id · $ref #/$defs/event_id
* verification_method · string · $ref ./common-ids.schema.json#/$defs/did_url
Arkret verification-method DID URL profile (identity/did-usage-and-verification.md section 2.2): lowercase method name, no query, required fragment, fragment limited to ASCII [A-Za-z0-9._:-]. Every verification_method-family field and every kid/key_ref a schema declares to be a DID URL MUST resolve to exactly this definition; values compare byte-for-byte with no URI normalization or percent-decoding.
pattern: ^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$
oneOf · oneOf[2] · object
* kind · const "recovery_candidate_device"
enum: "recovery_candidate_device"
* device_id · $ref #/$defs/device_id · $ref #/$defs/device_id
device_binding · object · $ref #/$defs/SessionGrantDeviceBinding
Authorization state committed into a standard device grant. An Account Authority MUST populate it verbatim from the Station TCB current-device decision, which is the only source of the origin-derived authorization Event and generation; it MUST NOT be taken from client input, a local cache or a private lookup. Stations compare it with the current active device generation on admission.
* device_id · string · $ref ./common-ids.schema.json#/$defs/device_id
pattern: ^ak:device:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$
* authorization_event_id · string
pattern: ^ak:event:[A-Za-z0-9_-]{44}$
* model_generation_ref · integer · $ref ./recovery-session.schema.json#/$defs/pcr_generation_ref
PCR-local monotonic generation. It MUST NOT equal or be derived from a DID versionId.
anyOf · anyOf[52] · object · $ref #/$defs/SessionGrantIntrospectRequestBody
Server-to-server session-grant introspection request. Exactly one of id / grant_jwt identifies the grant.
oneOf · oneOf[0] · ?
oneOf · oneOf[1] · ?
id · string · $ref ./common-ids.schema.json#/$defs/session_grant_id
Grant id. Mutually exclusive with grant_jwt.
pattern: ^ak:session_grant:[A-Za-z0-9_-]{44}$
grant_jwt · string
The signed grant JWT to introspect. Mutually exclusive with id.
audience_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
proof · object
Optional S2S holder confirmation signed by the session key bound into the grant. Stations validating /_arkret/self/* grant+DPoP requests do not require a client-carried introspection proof; they verify the request DPoP locally against the returned cnf_jkt.
* challenge · string
* proof_jwt · string
JWS over ak.session_grant.introspection_proof.v1 claims (session_grant_id, grant_jwt_digest, audience, challenge, issued_at, expires_at).
anyOf · anyOf[53] · object · $ref #/$defs/SessionGrantOutcome
* account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id · $ref #/$defs/did_core_id · $ref #/$defs/did_core_id
* station_id · $ref #/$defs/did_core_id · $ref #/$defs/did_core_id
device_id · string
pattern: ^ak:device:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$
* session_grant · string
Short-lived bearer/session grant bound to the requested principal, device and audience.
* expires_at · string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
* session_grant_id · string · $ref ./common-ids.schema.json#/$defs/session_grant_id
Stable id of the issued or rotated session grant. Returned for every grant so the client can reference, refresh, introspect or revoke this exact grant without re-parsing the opaque session_grant.
pattern: ^ak:session_grant:[A-Za-z0-9_-]{44}$
* session_public_key · string (canonical-public-jwk-jcs) · format=canonical-public-jwk-jcs
JWK of the holder/session key the grant is bound to (the device holder key). The client needs this to perform RFC 9421 PoP and to derive the DPoP cnf.jkt for /_arkret/self/* requests (api-conventions.md §3.2 / §3.3); returning it avoids a mandatory introspect round-trip before the first self-path request.
* audience_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* granted_scope · array<string>
items · string
previous_session_grant_id · string · $ref ./common-ids.schema.json#/$defs/session_grant_id
Present only on refresh. The predecessor grant atomically superseded by this successor.
pattern: ^ak:session_grant:[A-Za-z0-9_-]{44}$
anyOf · anyOf[54] · oneOf[2] · $ref #/$defs/SessionGrantRefreshRequestBody
Closed human-versus-Agent SessionGrant rotation union. Neither branch accepts a client-generated challenge or a generic proof_kind enum.
oneOf · oneOf[0] · object · $ref #/$defs/HumanSessionGrantRefreshRequest
* grant_jwt · string
Near-expiry human DPoP-bound SessionGrant presented as Authorization: DPoP plus a matching DPoP proof.
audience_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* device_id · string · $ref ./common-ids.schema.json#/$defs/device_id
pattern: ^ak:device:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$
* accepted_device_possession_proof · object · $ref #/$defs/AcceptedDevicePossessionProof
Accepted-device Ed25519 possession proof shared by human SessionGrant issue and refresh. The signature covers utf8('ak.session_grant_accepted_device_possession_proof.v1\n') followed by RFC 8785 JCS of this complete object with signature omitted. It is not a server challenge: freshness comes from the <=300 second signed window, the one-time account handoff or predecessor grant, the issuer request identity, and issuer-ledger exact replay. The origin Station MUST verify this proof with the durable current accepted-device key in the same linearization that evaluates current authorization.
allOf · allOf[0] · ?
* context · const "ak.session_grant_accepted_device_possession_proof.v1"
enum: "ak.session_grant_accepted_device_possession_proof.v1"
* purpose · string (enum)
enum: "session_grant_issue" "session_grant_refresh"
request_id · string
pattern: ^ak:request:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$
account_subject · string
pattern: ^sha256:[0-9a-f]{64}$
account_handoff_grant_digest · string
SHA-256 digest of the exact opaque DPoP-bound account_handoff_grant presented in Authorization; the credential itself MUST NOT enter the proof or logs.
pattern: ^sha256:[0-9a-f]{64}$
predecessor_session_grant_id · string · $ref ./common-ids.schema.json#/$defs/session_grant_id
pattern: ^ak:session_grant:[A-Za-z0-9_-]{44}$
* account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id · $ref #/$defs/did_core_id · $ref #/$defs/did_core_id
* station_id · $ref #/$defs/did_core_id · $ref #/$defs/did_core_id
* device_id · string · $ref ./common-ids.schema.json#/$defs/device_id
pattern: ^ak:device:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$
* audience_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* holder_jkt · string
RFC 7638 thumbprint of the DPoP holder key for the handoff or predecessor SessionGrant.
pattern: ^[A-Za-z0-9_-]{43}$
* session_intent_digest · string
Digest of the complete canonical immutable issue or refresh intent.
pattern: ^sha256:[0-9a-f]{64}$
* issued_at · string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
* expires_at · string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
* verification_method · string
DID URL of the accepted device key; its fragment MUST identify device_id and its bare did MUST project to account_id.principal_id.
pattern: ^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$
* signature · string
64-byte raw Ed25519 signature encoded as canonical unpadded base64url.
pattern: ^[A-Za-z0-9_-]{86}$
oneOf · oneOf[1] · object · $ref #/$defs/AgentSessionGrantRefreshRequest
Agent rotation binds the predecessor grant's agent_id, accepted agent_key_authorization_ref and proof.verification_method. Agent MLS endpoints have no device_id; a refresh carrying one is invalid.
* grant_jwt · string
Near-expiry Agent DPoP-bound SessionGrant presented as Authorization: DPoP plus a matching DPoP proof.
audience_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* principal_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* agent_key_authorization_ref · string · $ref ./account-operations.schema.json#/$defs/event_id
pattern: ^ak:event:[A-Za-z0-9_-]{44}$
* agent_session_refresh_proof · object · $ref #/$defs/AgentSessionRefreshProof
Current Agent runtime-key proof for SessionGrant rotation. It is a distinct branch from accepted human-device PoP and carries no client-generated challenge or polymorphic proof_kind.
* context · const "ak.agent_session_refresh_proof.v1"
enum: "ak.agent_session_refresh_proof.v1"
* request_canonical_digest · string
pattern: ^sha256:[0-9a-f]{64}$
* audience_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* issued_at · string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
* expires_at · string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
* verification_method · string
pattern: ^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$
* signature · string
pattern: ^[A-Za-z0-9_-]{86}$
anyOf · anyOf[55] · object · $ref #/$defs/SessionGrantReplayExpiredProblem
Closed RFC 9457 Problem Details extension members for session_grant_replay_expired. The named issuer-ledger record remains authoritative and no replacement grant is created under the same request identity.
* session_grant_id · string · $ref ./common-ids.schema.json#/$defs/session_grant_id
pattern: ^ak:session_grant:[A-Za-z0-9_-]{44}$
* state · const "expired"
Retained on purpose: this is an RFC 9457 Problem Details extension member on the failure path and names the issuer-ledger state that caused the rejection, so the problem document stays self-describing next to SessionGrantReplayTerminalProblem. It is not a success-only outcome constant.
enum: "expired"
anyOf · anyOf[56] · object · $ref #/$defs/SessionGrantReplayTerminalProblem
Closed RFC 9457 Problem Details extension members for session_grant_replay_terminal. The state is an exact durable issuer-ledger terminal state and no replacement grant is created under the same request identity.
* session_grant_id · string · $ref ./common-ids.schema.json#/$defs/session_grant_id
pattern: ^ak:session_grant:[A-Za-z0-9_-]{44}$
* state · string (enum)
enum: "revoked" "superseded"
anyOf · anyOf[57] · oneOf[3] · $ref #/$defs/SessionGrantRequestBody
Closed returning-human, Agent runtime or fresh-device recovery issuance union. OIDC authorization codes are consumed only by account_handoff_request_body and never by this operation.
oneOf · oneOf[0] · object · $ref #/$defs/HumanSessionGrantRequest
Returning-human issuance from an already bound account. Authorization is the DPoP-bound account_handoff_grant plus matching per-request DPoP; the body deliberately carries neither a second holder signature nor requested_scope.
* request_id · string
pattern: ^ak:request:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$
* principal_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* device_id · string · $ref ./common-ids.schema.json#/$defs/device_id
pattern: ^ak:device:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$
* audience_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* accepted_device_possession_proof · object · $ref #/$defs/AcceptedDevicePossessionProof
Accepted-device Ed25519 possession proof shared by human SessionGrant issue and refresh. The signature covers utf8('ak.session_grant_accepted_device_possession_proof.v1\n') followed by RFC 8785 JCS of this complete object with signature omitted. It is not a server challenge: freshness comes from the <=300 second signed window, the one-time account handoff or predecessor grant, the issuer request identity, and issuer-ledger exact replay. The origin Station MUST verify this proof with the durable current accepted-device key in the same linearization that evaluates current authorization.
allOf · allOf[0] · ?
* context · const "ak.session_grant_accepted_device_possession_proof.v1"
enum: "ak.session_grant_accepted_device_possession_proof.v1"
* purpose · string (enum)
enum: "session_grant_issue" "session_grant_refresh"
request_id · string
pattern: ^ak:request:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$
account_subject · string
pattern: ^sha256:[0-9a-f]{64}$
account_handoff_grant_digest · string
SHA-256 digest of the exact opaque DPoP-bound account_handoff_grant presented in Authorization; the credential itself MUST NOT enter the proof or logs.
pattern: ^sha256:[0-9a-f]{64}$
predecessor_session_grant_id · string · $ref ./common-ids.schema.json#/$defs/session_grant_id
pattern: ^ak:session_grant:[A-Za-z0-9_-]{44}$
* account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id · $ref #/$defs/did_core_id · $ref #/$defs/did_core_id
* station_id · $ref #/$defs/did_core_id · $ref #/$defs/did_core_id
* device_id · string · $ref ./common-ids.schema.json#/$defs/device_id
pattern: ^ak:device:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$
* audience_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* holder_jkt · string
RFC 7638 thumbprint of the DPoP holder key for the handoff or predecessor SessionGrant.
pattern: ^[A-Za-z0-9_-]{43}$
* session_intent_digest · string
Digest of the complete canonical immutable issue or refresh intent.
pattern: ^sha256:[0-9a-f]{64}$
* issued_at · string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
* expires_at · string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
* verification_method · string
DID URL of the accepted device key; its fragment MUST identify device_id and its bare did MUST project to account_id.principal_id.
pattern: ^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$
* signature · string
64-byte raw Ed25519 signature encoded as canonical unpadded base64url.
pattern: ^[A-Za-z0-9_-]{86}$
oneOf · oneOf[1] · object · $ref #/$defs/AgentSessionGrantRequest
Agent runtime session issuance is bound to principal_id (agent_id), proof.verification_method and the current accepted agent_key_authorization_ref. This closed branch MUST NOT carry a device_id or derive one from the Agent key.
* principal_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* requested_scope · array<string>
items · string
* agent_key_authorization_ref · string
`ak.profile.agent_auth.v1` overlay. Event ref of the accepted `ak.agent.key.authorize` that authorized the runtime key. REQUIRED when `proof.proof_kind="agent_key_proof"`; MUST be omitted for human session grants.
pattern: ^ak:event:[A-Za-z0-9_-]{44}$
* agent_scope_request · object
`ak.profile.agent_auth.v1` overlay. Narrowing hints for the issued session scope. Service-surface requested_scope values are intersected with the immutable provision requested_scope, accepted agent_key_scope and endpoint/resource policy; content actions are additionally intersected with independent effective Realm capability grants, participation, membership, history visibility and E2EE policy. Provision mandatory constraints remain in force at every layer. REQUIRED when `proof.proof_kind="agent_key_proof"`; MUST be omitted for human session grants. `track_names` is a request-side narrowing field only — the materialized session grant MUST express track scope via the canonical `allowed_tracks` constraint, not via a new `track_names` grant.
realm_ids · array<$ref ./common-ids.schema.json#/$defs/realm_id>
items · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
strand_ids · array<string>
items · string
pattern: ^ak:strand:[A-Za-z0-9_-]{44}$
track_names · array<string>
items · string
requested_scope_disclosure · object · $ref ./agent-requested-scope-disclosure.schema.json
Controller-signed, verifier-bound private disclosure of an Agent's immutable requested_scope. This object is authorization evidence, not a grant. It MUST travel only over an authenticated confidential presentation/operation channel and MUST NOT be written to a public DID Document, durable Realm Event, public registry, pairing code, or notification. The verifier consumes request_id/challenge once, validates the short presentation window, verifies a current controller proof, recomputes the requested-scope commitment against the accepted-at Agent DID commitment, and then applies the Agent ceiling subset rules. After successful one-time admission, an implementation MAY retain the object only as encrypted verifier-private evidence keyed by the recomputed digest, verifier_id and audience.
* schema · const "ak.schema.agent_requested_scope_disclosure.v1"
enum: "ak.schema.agent_requested_scope_disclosure.v1"
* request_id · string
Identifier of the verifier's authenticated private challenge request. It is single-use at verifier_id.
pattern: ^ak:request:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$
* agent_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* controller_principal_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* requested_scope · object · $ref ./event-payload.schema.json#/$defs/agent_key_scope
Agent scope object with two uses. In POST /_arkret/self/agents requested_scope it is the required immutable global Agent ceiling; in ak.agent.key.authorize it is a per-key ceiling that MAY be narrower but MUST be an actions/resources/constraints subset of the provision ceiling. It is never a capability grant. actions may contain service operation ids and content action tokens; an omitted action can never be restored by a key, Realm grant or session. resources constrain the service surface and may optionally narrow later content resources, but never authorize content by themselves. Provisioning and pairing do not materialize capability grants from this object; effective authority is the intersection of provision ceiling, key ceiling, independent Realm-scoped grants, session request, membership and policy, with participation applied as an additional deny gate.
* actions · $ref #/$defs/string_list · $ref #/$defs/string_list
Literal action ceiling. Every downstream key scope, grant or session action MUST appear here; action families, prefixes and subsumption do not widen it.
* resources · array<object>
Selector ceiling, not authorization. Each downstream selector must be covered by a parent selector. operation/service parents cover the same kind and matching explicit field and cannot carry content fields. The content-kind vocabulary is the ResourceSelector vocabulary except '*'; kind=realm covers every Realm-local content kind in the matching Realm and other content kinds cover only the same kind. Omitted parent realm_id is a cross-Realm ceiling wildcard and omitted exact ref is a same-kind/same-Realm wildcard. With no content selector, later Realm grants still choose concrete resources and no content wildcard is granted.
items · object
allOf · allOf[0] · ?
allOf · allOf[1] · ?
allOf · allOf[2] · ?
allOf · allOf[3] · ?
allOf · allOf[4] · ?
* kind · string (enum)
enum: "realm" "space" "circle" "strand" "message" "morph" "object" "relation" "view" "event" "actor" "schema" "policy" "invite" "notification" "read_cursor" "blob" "operation" "service"
realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
resource_ref · $ref #/$defs/object_ref · $ref #/$defs/object_ref
schema_ref · $ref #/$defs/non_empty_string · $ref #/$defs/non_empty_string
operation · $ref #/$defs/non_empty_string · $ref #/$defs/non_empty_string
service_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
constraints · array<$ref ./grant-constraint.schema.json>
Global mandatory constraints. Every effective key/grant/session evaluation MUST retain and AND these constraints; downstream scopes may add stricter constraints but MUST NOT omit or relax provision constraints.
items · object · $ref ./grant-constraint.schema.json
allOf · allOf[0] · ?
allOf · allOf[1] · ?
allOf · allOf[2] · ?
allOf · allOf[3] · ?
allOf · allOf[4] · ?
allOf · allOf[5] · ?
allOf · allOf[6] · ?
allOf · allOf[7] · ?
allOf · allOf[8] · ?
allOf · allOf[9] · ?
allOf · allOf[10] · ?
allOf · allOf[11] · ?
allOf · allOf[12] · ?
allOf · allOf[13] · ?
allOf · allOf[14] · ?
constraint_id · string
Optional stable identifier of this constraint within the grant; used for diagnostics and overrides.
pattern: ^(?!ak:)
* constraint_kind · string (enum)
Constraint family discriminator. v1 collapses what were 15 types into 8 by absorbing narrowly-scoped types into their conceptual parent: edit_window → temporal; container_move → scope_limitation; rate_limiting + resource_limit → quota; approval_workflow + accountability + device_session → claim_based (with constraint_subkind); encryption_requirement + visibility_control → confidentiality (with constraint_subkind). Use the optional 'constraint_subkind' field to indicate the original specialization where evaluation logic differs.
enum: "temporal" "field_access" "kind_restriction" "scope_limitation" "authority_control" "quota" "claim_based" "confidentiality"
* effect · string (enum)
enum: "allow" "deny" "quarantine" "require_review"
evaluation_class · string (enum)
Cacheability/dependency hint for the authorization evaluator. stateless = pure function of (constraint, op, now); grant_local = depends on the grant object only; realm_state = depends on the exact Realm authority revision (membership, policy_version, etc.); external = depends on data outside that authority state (claim revocation status, rate-limit counts, async approval). Each constraint_kind has a canonical evaluation_class declared in constraint-schema.md §2.3; implementations MAY tighten (e.g. grant_local → stateless) but MUST NOT loosen (e.g. external as stateless). Auth evaluators SHOULD use this hint to gate fast-path caching.
enum: "stateless" "grant_local" "realm_state" "external"
constraint_subkind · string (enum)
Optional discriminator within a constraint_kind. Standard values: claim_based.{claim,approval,accountability}; quota.{rate,resource}; confidentiality.{encryption,visibility}; temporal.{window,edit_window,redact_window,session}; authority_control.{applet_authority}. Per constraint-schema.md §2.2, device/session binding is NOT an independent constraint_subkind: it is the claim_based constraint_subkind=claim sub-case expressed via an accepted PCR device issuer. Implementations MAY require constraint_subkind for these families and fail closed on unknown values.
enum: "claim" "approval" "accountability" "rate" "resource" "encryption" "visibility" "window" "edit_window" "redact_window" "session" "applet_authority"
applies_to_actions · array<string>
Optional restriction of a temporal constraint to specific capability actions (e.g. ['ak.message.revise.own', 'ak.message.redact.own']). Action mismatch is neutral in the effect fold: satisfied for effect=allow and not matched for deny/quarantine/require_review.
items · string
pattern: ^ak\.[a-z0-9_]+(\.[a-z0-9_]+)*$
not_before · $ref #/$defs/timestamp · $ref #/$defs/timestamp
expires_at · $ref #/$defs/timestamp · $ref #/$defs/timestamp
recurrence · object
Recurrence rule for temporal constraints. Used by constraint-schema.md §3.1.
frequency · string (enum)
enum: "daily" "weekly" "monthly" "custom"
days · array<string (enum)>
items · …
recursion truncated at depth 8; see source schema for full shape
window_start · string
pattern: ^([01][0-9]|2[0-3]):[0-5][0-9](:[0-5][0-9])?$
window_end · string
pattern: ^([01][0-9]|2[0-3]):[0-5][0-9](:[0-5][0-9])?$
timezone · string
max_duration · string
ISO 8601 duration.
pattern: ^P(?:[0-9]+Y)?(?:[0-9]+M)?(?:[0-9]+W)?(?:[0-9]+D)?(?:T(?:[0-9]+H)?(?:[0-9]+M)?(?:[0-9]+S)?)?$
max_session_duration · string
pattern: ^P(?:[0-9]+Y)?(?:[0-9]+M)?(?:[0-9]+W)?(?:[0-9]+D)?(?:T(?:[0-9]+H)?(?:[0-9]+M)?(?:[0-9]+S)?)?$
inactivity_timeout · string
pattern: ^P(?:[0-9]+Y)?(?:[0-9]+M)?(?:[0-9]+W)?(?:[0-9]+D)?(?:T(?:[0-9]+H)?(?:[0-9]+M)?(?:[0-9]+S)?)?$
expires_after · string
ISO 8601 duration; used by approval_workflow constraint instead of expires_after_ms.
pattern: ^P(?:[0-9]+Y)?(?:[0-9]+M)?(?:[0-9]+W)?(?:[0-9]+D)?(?:T(?:[0-9]+H)?(?:[0-9]+M)?(?:[0-9]+S)?)?$
message_edit_window · string
pattern: ^P(?:[0-9]+Y)?(?:[0-9]+M)?(?:[0-9]+W)?(?:[0-9]+D)?(?:T(?:[0-9]+H)?(?:[0-9]+M)?(?:[0-9]+S)?)?$
message_redact_window · string
pattern: ^P(?:[0-9]+Y)?(?:[0-9]+M)?(?:[0-9]+W)?(?:[0-9]+D)?(?:T(?:[0-9]+H)?(?:[0-9]+M)?(?:[0-9]+S)?)?$
redact_after_window_allowed · boolean
condition · object
Conditional predicate for field_access and similar constraints. The `kind` value is a registered named condition from constraint-schema.md §4.1; unknown kinds MUST fail closed. Implementations MUST NOT introduce ad hoc string DSL predicates.
* kind · string (enum)
enum: "object_is_owned_by_actor" "actor_is_assignee" "actor_is_responsible" "actor_is_guardian" "actor_is_controller" "object_in_actor_container" "object_is_unencrypted" "object_is_encrypted" "always" "never"
allowed_write_fields · array<string>
items · string
denied_write_fields · array<string>
items · string
allowed_read_fields · array<string>
items · string
denied_read_fields · array<string>
items · string
sensitive_fields · array<string>
items · string
sensitive_handling · string (enum)
enum: "redact" "hash" "omit"
allowed_object_kinds · array<string>
items · string
denied_object_kinds · array<string>
items · string
allowed_morph_kinds · array<string>
items · string
denied_morph_kinds · array<string>
items · string
allowed_space_kinds · array<string>
Allowed Space kinds (e.g. 'board', 'list', or profile-registered kinds like 'swimlane', 'calendar_bucket'). Reducer/profile MUST validate kind value.
items · string
denied_space_kinds · array<string>
items · string
allowed_facets · array<string (enum)>
items · string (enum)
enum: "container" "replyable" "schedulable" "assignable" "stateful" "rankable" "reviewable" "notifiable" "documentable" "renderable"
denied_facets · array<string (enum)>
items · string (enum)
enum: "container" "replyable" "schedulable" "assignable" "stateful" "rankable" "reviewable" "notifiable" "documentable" "renderable"
allowed_view_ids · array<string>
items · string
pattern: ^ak:view:[A-Za-z0-9_-]{44}$
allowed_strand_ids · array<string>
items · string
pattern: ^ak:strand:[A-Za-z0-9_-]{44}$
denied_strand_ids · array<string>
items · string
pattern: ^ak:strand:[A-Za-z0-9_-]{44}$
allowed_space_ids · array<string>
items · string
pattern: ^ak:space:[A-Za-z0-9_-]{44}$
denied_space_ids · array<string>
items · string
pattern: ^ak:space:[A-Za-z0-9_-]{44}$
allowed_circle_ids · array<$ref ./common-ids.schema.json#/$defs/circle_id>
Limits Circle-scoped capability actions to the listed Circle ids. Used by ak.circle.manage / ak.circle.member.manage style grants; unconstrained Realm-wide Circle management grants are not a normal permission shape.
items · string · $ref ./common-ids.schema.json#/$defs/circle_id
pattern: ^ak:circle:[A-Za-z0-9_-]{44}$
allowed_session_ids · array<string>
Limits applet interop-session operations to the listed applet-defined session correlation ids.
items · string
pattern: ^(?!ak:)
allowed_view_kinds · array<string>
items · string
allowed_view_renderers · array<string>
items · string
denied_view_kinds · array<string>
items · string
denied_view_renderers · array<string>
items · string
allowed_relation_kinds · array<string>
items · string
allowed_from_container_refs · array<string>
items · string
pattern: ^ak:(space|strand|morph):[A-Za-z0-9_-]{44}$
allowed_to_container_refs · array<string>
items · string
pattern: ^ak:(space|strand|morph):[A-Za-z0-9_-]{44}$
wip_limit_override · boolean
example: false
allowed_tracks · array<string>
items · string
pattern: ^[a-z][a-z0-9_]{0,63}$
denied_tracks · array<string>
items · string
pattern: ^[a-z][a-z0-9_]{0,63}$
blob_presign_scope · object
Scope limiter for ak.self.blob.command.presign.v1 grants: allowed purposes plus optional blob/realm restrictions.
* allowed_purposes · array<string (enum)>
items · …
recursion truncated at depth 8; see source schema for full shape
blob_ref_pattern · string
realm_ids · array<$ref ./common-ids.schema.json#/$defs/realm_id>
items · …
recursion truncated at depth 8; see source schema for full shape
allowed_data_labels · array<string>
Data classification labels this grant may read, export, transform, or send to external endpoints.
items · string
pattern: ^[a-z][a-z0-9_]{0,63}$
allowed_endpoints · array<string>
Allowed outbound endpoint origins or deployment-approved endpoint patterns for applet / agent / connector operations.
items · string
max_authority_depth · integer
Maximum remaining authority hops. Bounded by the canonical authority-chain depth ceiling (4) defined in zh/conformance/scalability-constraints.md §3 and zh/authz/capabilities.md §10.2; reducers MUST reject grants declaring a larger value at accept time rather than only truncating during DFS.
authority_path_ids · array<$ref ./common-ids.schema.json#/$defs/did_core_id>
items · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
authority_regrant_allowed · boolean
authority_scope · string (enum)
enum: "narrowing_only" "same_scope" "custom"
applet_id · string · $ref ./common-ids.schema.json#/$defs/applet_id
Stable canonical Applet installation identity. Applet service authority is carried separately by service_id.
pattern: ^ak:applet:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$
executed_by · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind · …
recursion truncated at depth 8; see source schema for full shape
* account_id · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* kind · …
recursion truncated at depth 8; see source schema for full shape
* service_id · …
recursion truncated at depth 8; see source schema for full shape
registration_epoch · string
authority_control(constraint_subkind=applet_authority) binding to the canonical Applet registration epoch.
pattern: ^sha256:[0-9a-f]{64}$
blob_max_bytes · integer
blob_presign_max_ttl_seconds · integer
Maximum TTL, in seconds, that this grant permits for ak.blob.presign. The service must clamp requested max_age_seconds to the smaller of this value and deployment policy.
max_total_blob_bytes · integer
max_artifact_bytes · integer
Maximum artifact size in bytes for applet / agent / export operations.
max_operations · integer
Maximum number of distinct accepted idempotency identities in one UTC epoch-aligned fixed period. Enforcement is a linearizable check-and-reserve at one logical quota authority shared by every node in the enforcing service; per-node duplicated budgets and overshoot are forbidden.
period · string
ISO 8601 duration. For quota constraints, a stricter conditional schema permits only a non-zero fixed-length week/day/hour/minute/second duration; year/month durations are forbidden so every authority derives the same UTC epoch-aligned window id.
pattern: ^P(?:[0-9]+Y)?(?:[0-9]+M)?(?:[0-9]+W)?(?:[0-9]+D)?(?:T(?:[0-9]+H)?(?:[0-9]+M)?(?:[0-9]+S)?)?$
burst · integer
Optional token-bucket capacity at the same logical quota authority, capped by max_operations and refilled at max_operations/period. It never increases the fixed-window total budget.
constraint_scope · string (enum)
Closed v1 quota counting scope. Unknown values are schema violations and MUST fail closed. Quota counters are actor-bound; the enum selects the additional slicing dimension: actor only, actor+space, actor+realm, or actor across all nodes/regions of the enforcing service's global quota domain. global is not an implicit federation-wide counter. Every node in the service domain MUST share one logical linearizable quota authority.
enum: "per_actor" "per_space" "per_realm" "global"
max_resources · integer
resource_kind · string
approval_required · boolean
approval_mode · string (enum)
The only approval mode of v1. The approved write MUST NOT take effect before the approval evidence is verified and accepted in the same transaction (zh/authz/constraint-schema.md section 9.2.7). There is no second mode and no path that first materializes a proposal object and then approves that object.
enum: "before_commit"
approval_actor_ids · array<$ref ./common-ids.schema.json#/$defs/did_core_id>
items · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
approval_relation · string (enum)
Responsibility classification of this grant explicit approval_actor_ids roster. It never creates a second dynamic roster or supplies action/scope capability. Missing explicit roster cannot satisfy approval.
enum: "responsible" "controller" "guardian" "realm_admin" "custom"
timeout · string
Positive fixed ISO 8601 duration (week/day/hour/minute/second, no calendar year/month). Each approval vote is valid only when the target covering committed_at <= that vote input.approved_at + timeout, inclusive and with zero tolerance. The same rule applies to Event and operation targets; receiver clocks and first-seen timestamps never anchor it. Omission adds no grant-local age limit.
pattern: ^P(?:[0-9]+Y)?(?:[0-9]+M)?(?:[0-9]+W)?(?:[0-9]+D)?(?:T(?:[0-9]+H)?(?:[0-9]+M)?(?:[0-9]+S)?)?$
approval_threshold · oneOf[2]
Closed executable vote threshold: majority means floor(N/2)+1, unanimous means N, and a positive integer is the exact quorum. N is the distinct eligible approver set at the accepting authority cut. Omission means unanimous. A missing or empty eligible set, or an integer greater than N, cannot satisfy approval. Repeated signatures by one approver count once. Parameterless quorum/custom strings are schema violations.
example: "unanimous"
oneOf · oneOf[0] · string (enum)
enum: "majority" "unanimous"
oneOf · oneOf[1] · integer
accountability_required · boolean
guardian_approval_required · boolean
controller_approval_required · boolean
required_claims · array<object>
Conditional claim requirements. resource-selector-grammar.md §3.3 caps this array at 32 entries as a normative DoS guard; the schema enforces maxItems:32 so condition-selector grants cannot smuggle in unbounded claim objects.
items · object
anyOf · anyOf[0] · …
recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[1] · …
recursion truncated at depth 8; see source schema for full shape
* claim_kind · …
recursion truncated at depth 8; see source schema for full shape
issuer_id · …
recursion truncated at depth 8; see source schema for full shape
trusted_issuer_ids · …
recursion truncated at depth 8; see source schema for full shape
subject_matches_actor · …
recursion truncated at depth 8; see source schema for full shape
value_constraints · …
recursion truncated at depth 8; see source schema for full shape
organization_id · …
recursion truncated at depth 8; see source schema for full shape
status · …
recursion truncated at depth 8; see source schema for full shape
roles · …
recursion truncated at depth 8; see source schema for full shape
trusted_claim_issuer_ids · array<$ref ./common-ids.schema.json#/$defs/did_core_id>
items · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
claim_refresh_required · boolean
claim_max_age · string
pattern: ^P(?:[0-9]+Y)?(?:[0-9]+M)?(?:[0-9]+W)?(?:[0-9]+D)?(?:T(?:[0-9]+H)?(?:[0-9]+M)?(?:[0-9]+S)?)?$
allowed_history_access_values · array<string (enum)>
items · string (enum)
enum: "since_join" "all_history_for_current_members"
redacted_history_allowed · boolean
encryption_required · boolean
min_encryption_level · string (enum)
confidentiality(constraint_subkind=encryption) static floor: the minimum content-encryption mechanism the grant requires. Pure static declaration evaluated as stateless unless cross-checked against the scope's current MLS activation state (see constraint-schema.md section 12).
enum: "none" "mls_rfc9420" "external"
plaintext_fallback_allowed · boolean
confidentiality(constraint_subkind=encryption) static flag: whether the grant permits plaintext in a scope that has no accepted ak.mls.genesis. After activation the flag cannot restore plaintext; the write MUST be rejected with mls_activation_irreversible. See constraint-schema.md §12.
audit_trail_required · boolean
confidentiality(constraint_subkind=encryption) static flag: whether the grant requires an audit trail (e.g. active Audit Applet Binding). See constraint-schema.md §12.
key_rotation_period · string
pattern: ^P(?:[0-9]+Y)?(?:[0-9]+M)?(?:[0-9]+W)?(?:[0-9]+D)?(?:T(?:[0-9]+H)?(?:[0-9]+M)?(?:[0-9]+S)?)?$
max_key_age · string
pattern: ^P(?:[0-9]+Y)?(?:[0-9]+M)?(?:[0-9]+W)?(?:[0-9]+D)?(?:T(?:[0-9]+H)?(?:[0-9]+M)?(?:[0-9]+S)?)?$
key_backup_required · boolean
approved_key_issuer_ids · array<$ref ./common-ids.schema.json#/$defs/did_core_id>
items · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
depends_on_moderation_state · boolean
Cache-invalidation hint: when true, this grant's authorization decisions depend on the moderation_state typed current result (see capabilities.md §18.1) and the grant's cache entry MUST be invalidated when that typed current result changes. Default false: ordinary grants (ak.strand.update / ak.message.create / organization membership grants) do NOT take a cache hit on every moderation decision. v1 capabilities.md §18.1 lists three conditions where MUST be explicitly true (moderator-role grants, condition-selector subjects referencing moderation state, constraints referencing moderation queue / typed current result). Schema-side enforcement of condition (2) is in capability-grant.schema.json via if/then on actions[]; conditions (1) and (3) are reducer-side lint. Cache invalidation hint outside the eight constraint families; it does not participate in allow/deny evaluation and is documented in capabilities.md §6 / constraint-schema.md.
allowed_managed_actor_roles · array<string (enum)>
Ordinary authority_control permits only these accepted roles of the Applet bound by the parent applet_authority constraint; no arbitrary third-party regrant.
items · string (enum)
enum: "bot" "ghost"
(^x_[a-z][a-z0-9_]{0,63}$) · any
* verifier_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* audience · string
Exact origin, service audience, or canonical operation audience requested by verifier_id.
* challenge · string
Verifier-generated unpredictable challenge. The (verifier_id, request_id, challenge) tuple is single-use; replay MUST fail closed.
* issued_at · $ref #/$defs/timestamp · $ref #/$defs/timestamp
* expires_at · $ref #/$defs/timestamp · $ref #/$defs/timestamp
Presentation admission expiry. expires_at MUST be later than issued_at and expires_at - issued_at MUST NOT exceed 300 seconds. It does not change the immutable ceiling; it only bounds disclosure delivery/replay.
* proofs · array<$ref ./event-envelope.schema.json#/$defs/proof>
At least one current controller proof. The proof verification method MUST belong to controller_principal_id or one of its currently authorized devices. payload_digest is sha256(canonical_json(this object with proofs omitted)); detached JWS signs canonical_json({context:'ak.agent_requested_scope_disclosure_proof.v1', payload_digest, agent_id, controller_principal_id, verifier_id, audience, challenge, verification_method, created_at}).
items · object · $ref ./event-envelope.schema.json#/$defs/proof
Generic detached-JWS proof shape reused by non-Event schemas (snapshot signature, snapshot witness attestations, identity receipts, handle claims, etc.). MUST NOT be used as the shape of Event Envelope `producer_proof` — Event proofs reference $defs/event_proof and bind canonical Event bytes via `event_digest`. Non-Event signed objects MUST define an object-family signing-context constant and include it in the canonical proof binding object with payload_digest; the context constant is not a wire field in this generic shape. drift detection: `payload_digest#event_proof` in forbidden-wire-fields.json is the hard-reject mirror of this rule. New non-Event signed objects MAY $ref this shape; new signed Event-shaped objects MUST instead $ref event_proof.
* kind · string (enum)
Generic detached JWS proof over a canonical non-Event payload binding object that includes an object-family context constant.
enum: "detached_jws"
* verification_method · string
DID URL of the signing key for this non-Event detached proof. Same pattern as $defs/event_proof.verification_method; semantics are decoupled from Event proof (see $defs/event_proof for the Event-only shape).
pattern: ^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$
* payload_digest · $ref #/$defs/digest · $ref #/$defs/digest
Generic non-Event detached-proof hash. This $defs/proof shape is reused by non-Event schemas; Event.properties.producer_proof references $defs/event_proof and MUST use event_digest instead.
* created_at · $ref #/$defs/timestamp · $ref #/$defs/timestamp
domain · string
audience · oneOf[2]
oneOf · oneOf[0] · string
oneOf · oneOf[1] · array<string>
items · string
proof_purpose · string (enum)
Optional role discriminator for non-Event proofs. HandleClaim core, status and revocation carriers make issuer_attestation, holder_acceptance, status_attestation and revocation_authorization load-bearing. governance_authorization marks a resource-governance-key authorization (directory withdraw/takedown-appeal, discovery-directory.md 8.7.1). Generic proof consumers ignore it unless their object-family contract makes it load-bearing.
enum: "issuer_attestation" "holder_acceptance" "status_attestation" "revocation_authorization" "governance_authorization"
* jws · string
pattern: ^[A-Za-z0-9_-]+\.\.[A-Za-z0-9_-]+$
* dpop_binding_proof · object · $ref #/$defs/SessionGrantDpopBindingProof
`ak.profile.agent_auth.v1` overlay. DPoP proof JWT for the holder key that the issued session grant will bind to. REQUIRED when `proof.proof_kind="agent_key_proof"`; the Account Authority verifies the proof and materializes the resulting JWK thumbprint into the issued grant's `cnf.jkt` / session_public_key binding.
* proof_jwt · string
Frozen initial holder proof authenticated by the Agent request digest. HTTP DPoP is fresh per attempt and must bind the same public JWK thumbprint, not necessarily identical JWT bytes. First validation checks both proofs; completed exact ledger replay reuses validated body proof while revalidating fresh HTTP DPoP. See key-management section 3.6.1.
* proof · object
Closed initial Agent proof. Require 0 < expires_at-issued_at <= 300 seconds, issued_at <= now+30 seconds, and now < expires_at for first validation. No additional nonce. Exact completed issuer-ledger replay reuses durable one-shot verification, with fresh matching-holder HTTP DPoP.
* proof_kind · const "agent_key_proof"
enum: "agent_key_proof"
* challenge · string
Runtime-generated canonical unpadded Base64URL challenge with at least 128 bits of cryptographic randomness. Frozen for exact issuance retry; not a pairing handle or a server-issued challenge.
pattern: ^[A-Za-z0-9_-]+$
* request_canonical_digest · string
pattern: ^sha256:[0-9a-f]{64}$
* audience_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* issued_at · string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
* expires_at · string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
* verification_method · string
`ak.profile.agent_auth.v1` overlay. DID URL of the runtime signing key. REQUIRED when `proof_kind="agent_key_proof"`; the verifier MUST parse and adapter-validate its canonical bare did component, require project(did)=principal_id, and then validate the referenced key at the accepted method-history position. A did_core_id MUST NOT be used as a DID URL prefix or concatenated with a fragment. Projection mismatch returns `verification_method_principal_mismatch`. MUST be omitted for human proof kinds.
pattern: ^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$
* signature · string
Canonical unpadded Base64URL raw Ed25519 signature over RFC 8785 JCS of the entire proof with signature omitted; no Event JWS wrapper or extra prefix.
oneOf · oneOf[2] · object · $ref #/$defs/RecoverySessionGrantRequest
Fresh-device existing-principal recovery issuance. Authorization is the Bound AccountHandoff plus matching per-request DPoP. The Account Authority binds this request to its account/principal mapping and does not consume the handoff on success.
* credential_class · const "recovery_session"
enum: "recovery_session"
* request_id · string
pattern: ^ak:request:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$
* principal_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* device_id · string · $ref ./common-ids.schema.json#/$defs/device_id
pattern: ^ak:device:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$
* audience_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
anyOf · anyOf[58] · object · $ref #/$defs/SignalSubmitOutcome
Result of transient Signal admission. accepted=true means the service placed the encrypted envelope on the short-lived rail; it creates no Event, RealmCommit, authority-stream position or durable delivery receipt.
* accepted · boolean
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* envelope_digest · string
Digest of the admitted complete encrypted envelope, used only for short-lived replay suppression and local correlation.
pattern: ^(sha256|blake3):[0-9a-f]{64}$
dispatched_recipient_count · integer
Optional implementation hint for fanout recipients queued locally.
server_received_at · string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
anyOf · anyOf[59] · object · $ref #/$defs/SignedSessionGrantClaims
Canonical signed claims carried by an ak.session.grant JWT. Except for the fixed kind and derived jti, the closed issuance preimage fields are copied from these claims. credential_class and holder_binding are signed and jointly determine the authorization profile; recovery_session is never refreshable or upgradable and recovery completion issues a distinct standard credential. Verifiers MUST RFC 8785-canonicalize the complete claim-derived preimage, recompute SHA-256, prepend the active sha256 suite wire code, derive ak:session_grant:<44-char-token>, and require byte equality with jti. Changing either binding therefore changes the ID.
allOf · allOf[0] · ?
allOf · allOf[1] · ?
* kind · const "ak.session.grant"
enum: "ak.session.grant"
* jti · string · $ref ./common-ids.schema.json#/$defs/session_grant_id
pattern: ^ak:session_grant:[A-Za-z0-9_-]{44}$
* issuer_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* issuance_nonce · string
Canonical unpadded Base64URL encoding of the issuer-generated 256-bit issuance nonce. Exact replay reuses the same nonce, issuance preimage, grant ID and JWT.
pattern: ^[A-Za-z0-9_-]{43}$
* account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id · $ref #/$defs/did_core_id · $ref #/$defs/did_core_id
* station_id · $ref #/$defs/did_core_id · $ref #/$defs/did_core_id
* session_public_key · string (canonical-public-jwk-jcs) · format=canonical-public-jwk-jcs
A supported public JWK serialized as its exact RFC 8785 JCS UTF-8 string. Producers MUST parse and canonicalize input before signing; consumers MUST reject strings whose parsed JWK re-serialization is not byte-identical. Private JWK members are forbidden.
* audience_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* scopes · array<string>
items · string
* not_before · string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
* expires_at · string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
* session_id · string
pattern: ^(?!ak:)
* credential_class · string (enum) · $ref #/$defs/SessionGrantCredentialClass
Closed credential class. recovery_session is a <=15 minute, non-refreshable, DPoP-bound candidate-device grant restricted to the exact recovery operation set; recovery completion issues a distinct standard grant.
enum: "standard" "recovery_session"
device_binding · object · $ref #/$defs/SessionGrantDeviceBinding
Authorization state committed into a standard device grant. An Account Authority MUST populate it verbatim from the Station TCB current-device decision, which is the only source of the origin-derived authorization Event and generation; it MUST NOT be taken from client input, a local cache or a private lookup. Stations compare it with the current active device generation on admission.
* device_id · string · $ref ./common-ids.schema.json#/$defs/device_id
pattern: ^ak:device:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$
* authorization_event_id · string
pattern: ^ak:event:[A-Za-z0-9_-]{44}$
* model_generation_ref · integer · $ref ./recovery-session.schema.json#/$defs/pcr_generation_ref
PCR-local monotonic generation. It MUST NOT equal or be derived from a DID versionId.
* holder_binding · oneOf[3] · $ref ./principal-operations.schema.json#/$defs/session_grant_holder_binding
oneOf · oneOf[0] · object
* kind · const "human_device"
enum: "human_device"
* device_binding · $ref #/$defs/opaque_id · $ref #/$defs/opaque_id
oneOf · oneOf[1] · object
* kind · const "agent_runtime"
enum: "agent_runtime"
* agent_id · $ref #/$defs/did_core_id · $ref #/$defs/did_core_id
* agent_key_authorization_ref · $ref #/$defs/event_id · $ref #/$defs/event_id
* verification_method · string · $ref ./common-ids.schema.json#/$defs/did_url
Arkret verification-method DID URL profile (identity/did-usage-and-verification.md section 2.2): lowercase method name, no query, required fragment, fragment limited to ASCII [A-Za-z0-9._:-]. Every verification_method-family field and every kid/key_ref a schema declares to be a DID URL MUST resolve to exactly this definition; values compare byte-for-byte with no URI normalization or percent-decoding.
pattern: ^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$
oneOf · oneOf[2] · object
* kind · const "recovery_candidate_device"
enum: "recovery_candidate_device"
* device_id · $ref #/$defs/device_id · $ref #/$defs/device_id
proof_kind · string (enum)
enum: "account_handoff" "agent_key_proof"
scope_details · object
anyOf · anyOf[60] · oneOf[2] · $ref #/$defs/CommittedEventView
Caller-scoped, non-durable read representation pairing one RealmCommit with either the exact producer-signed Event or a minimal withheld marker. It has no independent identity, signature or persistence semantics and is never reducer input.
oneOf · oneOf[0] · object
* commit · object · $ref ./realm-commit.schema.json
The only shared Realm acceptance, ordering, finality and replication record. Every visibility scope has an authority-signed predecessor chain.
allOf · allOf[0] · ?
* commit_id · string · $ref ./common-ids.schema.json#/$defs/realm_commit_id
Content-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern: ^ak:realm_commit:[A-Za-z0-9_-]{44}$
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* stream_ref · $ref #/$defs/stream_ref · $ref #/$defs/stream_ref
* stream_position · integer
* previous_commit_ref · oneOf[2]
oneOf · oneOf[0] · string · $ref ./common-ids.schema.json#/$defs/realm_commit_id
Content-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern: ^ak:realm_commit:[A-Za-z0-9_-]{44}$
oneOf · oneOf[1] · null
* event_ref · string · $ref ./common-ids.schema.json#/$defs/event_id
Complete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern: ^ak:event:[A-Za-z0-9_-]{44}$
* governance_generation · integer
Tenure counter of the governing Station that signed this Commit; it advances only on an accepted ak.realm.governance_station.change. It is not the Realm authority-root delegation generation of typed-current-result.schema.json#/$defs/realm_authority_root_value, which advances only on ak.realm.authority.reset.
* authority_ref · oneOf[2]
oneOf · oneOf[0] · string · $ref ./common-ids.schema.json#/$defs/event_id
Complete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern: ^ak:event:[A-Za-z0-9_-]{44}$
oneOf · oneOf[1] · string · $ref ./common-ids.schema.json#/$defs/realm_authority_handoff_id
Content-addressed identity of one closed old-to-new Realm authority handoff.
pattern: ^ak:realm_authority_handoff:[A-Za-z0-9_-]{44}$
* committed_at · string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
producer_signer_fact_digest · string · $ref ./account-operations.schema.json#/$defs/sha256_digest
Fixed SHA256 over RFC8785 JCS of the original immutable Human or Applet Service producer fact, excluding the outer target coordinate. Freeze before Commit identity/signature and retain with acceptance; exact replay, replica and handoff preserve this original digest.
pattern: ^sha256:[0-9a-f]{64}$
* signature · allOf[2] · $ref ./detached-object-signature.schema.json#/$defs/realm_commit_signature
allOf · allOf[0] · anyOf[61] · $ref #
Canonical DTOs reachable from current authority-commit operations. Every definition is part of the current operation closure.
anyOf · anyOf[0] · object · $ref #/$defs/AcceptedDevicePossessionProof
Accepted-device Ed25519 possession proof shared by human SessionGrant issue and refresh. The signature covers utf8('ak.session_grant_accepted_device_possession_proof.v1\n') followed by RFC 8785 JCS of this complete object with signature omitted. It is not a server challenge: freshness comes from the <=300 second signed window, the one-time account handoff or predecessor grant, the issuer request identity, and issuer-ledger exact replay. The origin Station MUST verify this proof with the durable current accepted-device key in the same linearization that evaluates current authorization.
allOf · allOf[0] · ?
* context · const "ak.session_grant_accepted_device_possession_proof.v1"
enum: "ak.session_grant_accepted_device_possession_proof.v1"
* purpose · string (enum)
enum: "session_grant_issue" "session_grant_refresh"
request_id · string
pattern: ^ak:request:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$
account_subject · string
pattern: ^sha256:[0-9a-f]{64}$
account_handoff_grant_digest · string
SHA-256 digest of the exact opaque DPoP-bound account_handoff_grant presented in Authorization; the credential itself MUST NOT enter the proof or logs.
pattern: ^sha256:[0-9a-f]{64}$
predecessor_session_grant_id · string · $ref ./common-ids.schema.json#/$defs/session_grant_id
pattern: ^ak:session_grant:[A-Za-z0-9_-]{44}$
* account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id · $ref #/$defs/did_core_id · $ref #/$defs/did_core_id
* station_id · $ref #/$defs/did_core_id · $ref #/$defs/did_core_id
* device_id · string · $ref ./common-ids.schema.json#/$defs/device_id
pattern: ^ak:device:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$
* audience_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* holder_jkt · string
RFC 7638 thumbprint of the DPoP holder key for the handoff or predecessor SessionGrant.
pattern: ^[A-Za-z0-9_-]{43}$
* session_intent_digest · string
Digest of the complete canonical immutable issue or refresh intent.
pattern: ^sha256:[0-9a-f]{64}$
* issued_at · string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
* expires_at · string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
* verification_method · string
DID URL of the accepted device key; its fragment MUST identify device_id and its bare did MUST project to account_id.principal_id.
pattern: ^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$
* signature · string
64-byte raw Ed25519 signature encoded as canonical unpadded base64url.
pattern: ^[A-Za-z0-9_-]{86}$
anyOf · anyOf[1] · oneOf[2] · $ref #/$defs/ActorPrivateEventSubmitOutcome
Closed outcome of ak.self.actor_private_events.command.submit.v1, discriminated by event_kind. accepted_event_id is the event_id of the accepted Event, and an exact retry returns the first stored outcome. Only ak.device.push_route carries the accepted per-route revision its next write must name as expected_server_revision. No RealmCommit exists for these writes.
oneOf · oneOf[0] · object
* event_kind · const "ak.device.push_route"
enum: "ak.device.push_route"
* accepted_event_id · string · $ref #/$defs/EventId
pattern: ^ak:event:[A-Za-z0-9_-]{44}$
* revision · integer
oneOf · oneOf[1] · object
* event_kind · string (enum)
enum: "ak.agent.action_reject" "ak.agent.action_request" "ak.agent.draft.propose"
* accepted_event_id · string · $ref #/$defs/EventId
pattern: ^ak:event:[A-Za-z0-9_-]{44}$
anyOf · anyOf[2] · object · $ref #/$defs/ActorPrivateEventSubmitRequestBody
Request of ak.self.actor_private_events.command.submit.v1: exactly one caller-signed actor-private Event of a kind that has no dedicated submit operation. The service validates the exact Event bytes and MUST NOT rebuild the payload or co-sign. No approval sidecar exists because no approval layer applies to these kinds. zh/models/actor-private-effects.md section 2.1.
* event · object · $ref ./event-envelope.schema.json
Closed producer-signed Event. Shared persistent Events become final only when the current Realm governance Station issues a RealmCommit in the derived Realm, Circle, or Sidecar stream.
allOf · allOf[0] · ?
allOf · allOf[1] · ?
allOf · allOf[2] · ?
allOf · allOf[3] · ?
allOf · allOf[4] · ?
allOf · allOf[5] · $ref #/$defs/registered_admission_shape · $ref #/$defs/registered_admission_shape
allOf · allOf[6] · $ref #/$defs/registered_execution_shape · $ref #/$defs/registered_execution_shape
allOf · allOf[7] · ?
allOf · allOf[8] · ?
allOf · allOf[9] · ?
allOf · allOf[10] · ?
allOf · allOf[11] · ?
allOf · allOf[12] · ?
allOf · allOf[13] · ?
allOf · allOf[14] · ?
allOf · allOf[15] · ?
allOf · allOf[16] · ?
allOf · allOf[17] · ?
allOf · allOf[18] · ?
allOf · allOf[19] · ?
allOf · allOf[20] · ?
allOf · allOf[21] · ?
allOf · allOf[22] · ?
allOf · allOf[23] · ?
allOf · allOf[24] · ?
allOf · allOf[25] · ?
allOf · allOf[26] · ?
allOf · allOf[27] · ?
allOf · allOf[28] · ?
allOf · allOf[29] · ?
allOf · allOf[30] · ?
allOf · allOf[31] · ?
allOf · allOf[32] · ?
allOf · allOf[33] · ?
allOf · allOf[34] · ?
allOf · allOf[35] · ?
allOf · allOf[36] · ?
allOf · allOf[37] · ?
allOf · allOf[38] · ?
allOf · allOf[39] · ?
allOf · allOf[40] · ?
allOf · allOf[41] · ?
allOf · allOf[42] · ?
allOf · allOf[43] · ?
allOf · allOf[44] · ?
allOf · allOf[45] · ?
allOf · allOf[46] · ?
allOf · allOf[47] · ?
allOf · allOf[48] · ?
allOf · allOf[49] · ?
allOf · allOf[50] · ?
allOf · allOf[51] · ?
allOf · allOf[52] · ?
allOf · allOf[53] · ?
allOf · allOf[54] · ?
allOf · allOf[55] · ?
allOf · allOf[56] · ?
allOf · allOf[57] · ?
allOf · allOf[58] · ?
allOf · allOf[59] · ?
allOf · allOf[60] · ?
allOf · allOf[61] · ?
allOf · allOf[62] · ?
allOf · allOf[63] · ?
allOf · allOf[64] · ?
allOf · allOf[65] · ?
allOf · allOf[66] · ?
allOf · allOf[67] · ?
allOf · allOf[68] · ?
allOf · allOf[69] · ?
allOf · allOf[70] · ?
allOf · allOf[71] · ?
allOf · allOf[72] · ?
allOf · allOf[73] · ?
allOf · allOf[74] · ?
allOf · allOf[75] · ?
allOf · allOf[76] · ?
allOf · allOf[77] · ?
allOf · allOf[78] · ?
allOf · allOf[79] · ?
allOf · allOf[80] · ?
allOf · allOf[81] · ?
allOf · allOf[82] · ?
allOf · allOf[83] · ?
allOf · allOf[84] · ?
allOf · allOf[85] · ?
allOf · allOf[86] · ?
allOf · allOf[87] · ?
allOf · allOf[88] · ?
allOf · allOf[89] · ?
allOf · allOf[90] · ?
allOf · allOf[91] · ?
allOf · allOf[92] · ?
allOf · allOf[93] · ?
allOf · allOf[94] · ?
allOf · allOf[95] · ?
allOf · allOf[96] · ?
allOf · allOf[97] · ?
allOf · allOf[98] · ?
allOf · allOf[99] · ?
allOf · allOf[100] · ?
allOf · allOf[101] · ?
allOf · allOf[102] · ?
allOf · allOf[103] · ?
allOf · allOf[104] · ?
allOf · allOf[105] · ?
allOf · allOf[106] · ?
allOf · allOf[107] · ?
allOf · allOf[108] · ?
allOf · allOf[109] · ?
allOf · allOf[110] · ?
allOf · allOf[111] · ?
allOf · allOf[112] · ?
allOf · allOf[113] · ?
allOf · allOf[114] · ?
allOf · allOf[115] · ?
allOf · allOf[116] · ?
allOf · allOf[117] · ?
allOf · allOf[118] · ?
allOf · allOf[119] · ?
allOf · allOf[120] · ?
allOf · allOf[121] · ?
allOf · allOf[122] · ?
allOf · allOf[123] · ?
allOf · allOf[124] · ?
allOf · allOf[125] · ?
allOf · allOf[126] · ?
allOf · allOf[127] · ?
allOf · allOf[128] · ?
allOf · allOf[129] · ?
allOf · allOf[130] · ?
allOf · allOf[131] · ?
allOf · allOf[132] · ?
allOf · allOf[133] · ?
allOf · allOf[134] · ?
allOf · allOf[135] · ?
allOf · allOf[136] · ?
allOf · allOf[137] · ?
allOf · allOf[138] · ?
allOf · allOf[139] · ?
allOf · allOf[140] · ?
* event_id · string · $ref ./common-ids.schema.json#/$defs/event_id
Complete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern: ^ak:event:[A-Za-z0-9_-]{44}$
* kind · string
Standard ak.* Event kinds MUST appear in artifacts/registry/event-kind-registry.json. State convergence is defined by the registered pure reducer over kind + payload; producers do not submit typed current result writes.
pattern: ^ak\.[a-z0-9_]+(\.[a-z0-9_]+)*$
realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* scope_ref · $ref #/$defs/scope_ref · $ref #/$defs/scope_ref
Required producer-signed security scope. The closed union is ordinary existing realm, circle, or native sidecar scope plus the create-only realm_genesis exception. It enters proof.event_digest and E2EE AAD. Reducers independently derive the exact scope from schema-validated payload and accepted references; missing dependencies, nonexistent scope, realm_id mismatch, omitted sidecar_id, substituting circle for sidecar, or any unequal field is fail closed. Sidecar domain Event kinds remain Extension-owned; recognizing this native security shape does not make Kernel interpret the Sidecar reducer. Exact product targets remain inside recipient-visible ciphertext.
* actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · …
recursion truncated at depth 8; see source schema for full shape
executed_by · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · …
recursion truncated at depth 8; see source schema for full shape
authorization_ref · oneOf[6]
Optional. Required when executed_by is present. It identifies an accepted Grant, delegation Event, DID-document delegation, or one of the closed profile-specific authority constants. The current governance Station evaluates the reference against the target stream's committed state.
oneOf · oneOf[0] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[2] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[3] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[4] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[5] · …
recursion truncated at depth 8; see source schema for full shape
applet_id · $ref #/$defs/applet_id · $ref #/$defs/applet_id
Optional signed Applet provenance. Required by ak.profile.applet_* when the Event is introduced by an Applet, Ghost Actor, bridge, or delegated applet path. Enters canonical event bytes and therefore is covered by proof.event_digest. When present, authorization_ref MUST also be present and resolve to a real active registration/capability grant binding this applet_id, registration_epoch, action and resource per zh/extensions/applet-integration.md sections 4, 8 and 11. Service-actor self-signature proves provenance but is not an authorization substitute. Capability-gated actions require a grant covering action/resource. For subject_only operations the referenced grant binds only the exact active install and cannot replace the subject signature, FSM or independent action authority. Service self-authored Events use ActorId.service; the install grant subject MUST be the same exact ActorId.service as its producer; hosting Station and effective scope are verified separately without coercing a Service into an account variant.
external_ref · $ref #/$defs/external_ref · $ref #/$defs/external_ref
Optional signed external provenance reference for Applet / bridge-originated Events. It is covered by event_digest and MUST NOT be carried only in unsigned when used for loop prevention, audit, or external-message idempotency. Must not contain unauthorized external plaintext.
* created_at · $ref #/$defs/canonical_event_timestamp · $ref #/$defs/canonical_event_timestamp
semantic_refs · array<$ref #/$defs/semantic_ref>
Optional semantic refs with role. Omit when there are no semantic references; an explicitly empty array is not canonical. Admission selectors determine any required references. PCR policy recovery has no DID-root anchor reference; its policy/session/replacement-key authority is verified separately.
items · …
recursion truncated at depth 8; see source schema for full shape
* payload · object
* producer_proof · $ref #/$defs/event_proof · $ref #/$defs/event_proof
The Event's sole portable producer proof. Storage receipts are separate objects and never authorize this Event. producer_proof and unsigned remain outside the canonical Event digest. Exact retries preserve the verified producer proof.
anyOf · anyOf[3] · object · $ref #/$defs/AccountCursorRevokeOutcome
* revoked · boolean
expires_at · string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
anyOf · anyOf[4] · object · $ref #/$defs/AccountCursorRevokeRequestBody
* cursor · string
pattern: ^ak:cursor:[A-Za-z0-9_-]+$
* reason_code · string
pattern: ^[a-z][a-z0-9_]{0,63}$
revoke_scope · string (enum)
enum: "this_cursor" "same_device" "same_session"
example: "this_cursor"
anyOf · anyOf[5] · object · $ref #/$defs/AccountLogoutOutcome
* revoked · boolean
Whether a live device session was revoked.
anyOf · anyOf[6] · object · $ref #/$defs/AccountLogoutRequestBody
anyOf · anyOf[7] · object · $ref #/$defs/AuthSessionLogoutOutcome
* grant_chain_terminated · boolean
Whether the grant rotation chain is now unable to refresh, including the already-terminated idempotent case.
* auth_session_logged_out · boolean
Whether the underlying Auth-side browser/auth session is now logged out, including the already-logged-out idempotent case.
anyOf · anyOf[8] · object · $ref #/$defs/AuthSessionLogoutRequestBody
Service-to-service Account Authority to Auth Server request that logs out the Auth-side session owning a ak.session.grant rotation chain.
* grant_jwt · string
Session grant used to locate the Auth-side session and its rotation chain.
logout_request_digest · string
Optional digest of the validated client-visible account /logout request that caused this S2S sub-operation.
pattern: ^(sha256|blake3):[0-9a-f]{64}$
validated_at · string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
reason_code · string (enum)
Reason for logging out the Auth-side session. v1 defines only account_logout for this S2S sub-operation.
enum: "account_logout"
anyOf · anyOf[9] · object · $ref #/$defs/AuthzCheckOutcome
ak.self.authz.read.check.v1 diagnostic/preflight decision. See zh/authz/capabilities.md §18. This response is advisory; canonical Event admission remains authoritative.
* decision · string (enum)
`allow` / `hard_deny` are terminal decisions. `soft_deny` is an evaluated policy soft refusal. `quarantine` / `require_review` are local moderation outcomes. Transient dependency or freshness failures are reported through `freshness_state`, `reason_code`, and `retry_after_ms`, not as policy decision values.
enum: "allow" "soft_deny" "hard_deny" "quarantine" "require_review"
matched_grants · array<object>
items · object
applied_constraints · array<object>
items · object
policy_results · array<object>
items · object
missing_proofs · array<object>
items · object
checkpoint · object
freshness_state · string (enum)
Checkpoint freshness classification for revocation-sensitive decisions; see zh/authz/capabilities.md §18.2.
enum: "fresh" "stale" "unknown"
last_known_checkpoint_age_ms · integer
Age of the newest revocation/auth checkpoint evidence used for this decision. Present when freshness_state is stale or unknown.
authority_status · string (enum)
Coarse status of the current governance Station and committed-stream source used to diagnose stale or unknown revocation freshness.
enum: "fresh" "lagging" "unreachable" "unknown"
cache_expires_at · string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
reason_code · string
Registered reason code. High-risk stale or unknown revocation freshness returns revocation_freshness_unknown.
pattern: ^[a-z][a-z0-9_]{0,63}$
retry_after_ms · integer
Set when `freshness_state ∈ {stale,unknown}` or a retryable `reason_code` is present; client SHOULD back off this amount before retry.
obligations · array<object>
Additional local preflight obligations the caller MUST satisfy before the action proceeds.
items · object
anyOf · anyOf[10] · object · $ref #/$defs/AuthzCheckRequestBody
ak.self.authz.read.check.v1 advisory local authorization preflight. It is never a cross-service authorization fact and cannot replace the current governance Station's admission decision.
* actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind · …
recursion truncated at depth 8; see source schema for full shape
* account_id · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* kind · …
recursion truncated at depth 8; see source schema for full shape
* service_id · …
recursion truncated at depth 8; see source schema for full shape
* action · string
Capability action id (e.g. `ak.strand.update`).
resource · object
Optional resource selector (Realm / Strand / Space / Morph / etc.).
context · object
Optional decision context — claim presentations, checkpoint reference, request metadata.
anyOf · anyOf[11] · object · $ref #/$defs/BlobPresignOutcome
* url · string (uri) · format=uri
Fully-qualified URL clients can pass to browser primitives. Contains the `presign` query parameter, `blob_ref`, and a presign envelope bound to `realm_id` for Realm-owned blobs.
pattern: ^https?://
* expires_at · string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
purpose · string
Echo of the issued `purpose`.
anyOf · anyOf[12] · object · $ref #/$defs/BlobPresignRequestBody
* blob_ref · string · $ref ./common-ids.schema.json#/$defs/blob_ref
Content-addressed reference to exact Blob bytes. The embedded suite and digest are the sole wire commitment to those bytes; sibling content/ciphertext digest mirrors are forbidden.
pattern: ^ak:blob:(?:sha256|blake3):[0-9a-f]{64}$
realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
max_age_seconds · integer
Client-requested TTL upper bound. Server clamps to the smaller of this value, the issuing grant's `blob_presign_max_ttl_seconds` constraint, and the deployment-level cap.
purpose · string (enum)
Intended rendering / download mode. Servers MAY apply purpose-specific Content-Disposition or rate limits.
enum: "media_inline" "thumbnail" "download"
anyOf · anyOf[13] · object · $ref #/$defs/CallMediaTokenExchangeOutcome
allOf · allOf[0] · ?
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* call_id · string
pattern: ^ak:call:[A-Za-z0-9_-]{44}$
* actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind · …
recursion truncated at depth 8; see source schema for full shape
* account_id · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* kind · …
recursion truncated at depth 8; see source schema for full shape
* service_id · …
recursion truncated at depth 8; see source schema for full shape
* device_id · string
pattern: ^ak:device:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$
* focus_id · string
pattern: ^(?!ak:)
* connect_url · string (uri) · format=uri
pattern: ^(https|wss)://
* backend_token · ?
Closed branch selected by backend_kind: arkret_native uses the typed signature object; every other v1 backend uses a non-empty opaque string.
* participant_id · string
SFU-local short handle, scope `(call_id, focus_id, sfu_did)`. UUIDv7-form rtc_participant typed ID.
pattern: ^ak:rtc_participant:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$
* participant_binding · object · $ref ./event-payload.schema.json#/$defs/participant_binding
Token issuer's signed commitment over (realm_id, call_id, focus_id, actor_id, device_id, participant_id, expires_at) for a media participant. See crypto-media/media-service-binding.md §3 and crypto-media/call-state.md §4.1. v1 uses the single scheme ak.media.participant_binding.v1.
* expires_at · $ref #/$defs/timestamp · $ref #/$defs/timestamp
* issuer_kid · string
DID URL (with fragment) of the token issuer service signing key. MUST resolve to a service DID present in the current-epoch ak.realm.media_service.service_id.
pattern: ^did:[a-z0-9]+:[^\s?]+#[^\s#?]+$
* sig · $ref #/$defs/non_empty_string · $ref #/$defs/non_empty_string
* expires_at · string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
* backend_kind · string (enum)
Backend binding type identifier (livekit / arkret_native / etc.).
enum: "livekit" "mediasoup" "janus" "arkret_native" "moq_relay"
anyOf · anyOf[14] · object · $ref #/$defs/CallMediaTokenExchangeRequestBody
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* call_id · string
pattern: ^ak:call:[A-Za-z0-9_-]{44}$
* actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind · …
recursion truncated at depth 8; see source schema for full shape
* account_id · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* kind · …
recursion truncated at depth 8; see source schema for full shape
* service_id · …
recursion truncated at depth 8; see source schema for full shape
* device_id · string
Stable protocol endpoint identifier. REQUIRED for agent_key_proof and covered by request_canonical_digest; the Account Authority MUST persist and return the same value in the issued grant so Stations can bind MLS KeyPackage ownership, Welcome routing, consume/revoke operations, refresh, and restart recovery to one endpoint. It MUST NOT be derived from a session or grant id.
pattern: ^ak:device:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$
* focus_id · string
pattern: ^(?!ak:)
capability_refs · array<string>
items · string
pattern: ^ak:grant:[A-Za-z0-9_-]{44}$
desired_media · object
audio · boolean
video · boolean
screen · boolean
anyOf · anyOf[15] · object · $ref #/$defs/DeviceMessagesAckOutcome
* pruned_count · integer
Number of recipient deliveries acknowledged by this token: DeviceMessage rows deleted plus Welcome rows marked delivered and retained for audit; zero is legal for a repeated or older token.
anyOf · anyOf[16] · object · $ref #/$defs/DeviceMessagesAckRequestBody
* ack_token · string
Acknowledgement token previously issued to the same authenticated recipient endpoint by account subscribe or the recipient-delivery list. It cumulatively prunes both DeviceMessage and MlsWelcomeDelivery queue items through the bound position, only after every covered item was durably processed. Unknown / expired / cross-bound tokens MUST be rejected with param_invalid (reason invalid_ack_token) without deleting anything. Naturally idempotent; no Idempotency-Key required.
anyOf · anyOf[17] · object · $ref #/$defs/DeviceMessagesGetOutcome
allOf · allOf[0] · ?
* deliveries · array<$ref ./account-subscribe-frame.schema.json#/$defs/recipient_delivery>
Ordered recipient-private queue items, each discriminated as an unchanged DeviceMessageEnvelope or MlsWelcomeDelivery. These are not shared Event Envelope objects.
items · oneOf[2] · $ref ./account-subscribe-frame.schema.json#/$defs/recipient_delivery
One exact recipient-private queue item. The discriminator selects an unchanged DeviceMessageEnvelope or producer-signed MlsWelcomeDelivery; neither payload is rewritten into the other.
oneOf · oneOf[0] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · …
recursion truncated at depth 8; see source schema for full shape
ack_token · string
Server-issued opaque acknowledgement token, REQUIRED whenever deliveries[] is non-empty. Covers both delivery kinds in this page and earlier items for the authenticated recipient endpoint. Queue deletion happens only through ak.self.device_messages.command.ack.v1 with this token, never through the after= read cursor (client-sync.md §10.1).
next_cursor · string
Read-only continuation position; advancing it MUST NOT delete queued messages.
* has_more · boolean
limited · boolean
lost · boolean
SHOULD be true only for a durably evidenced historical gap or failure since this recipient endpoint's last acknowledged position; normal expiry and capacity MUST NOT delete unacknowledged deliveries of either kind. Clients MUST re-establish MLS/key readiness when true.
anyOf · anyOf[18] · object · $ref #/$defs/DeviceMessagesSendOutcome
* delivered · object
Principal-id to device-id map for messages accepted for delivery.
* unknown_devices · object
Principal-id to device-id map for recipient targets that are not deliverable. Membership alone is the whole result: unknown, revoked, fenced or otherwise undeliverable devices are indistinguishable. A sender-side invalid expires_at never lands here; it fails the whole request.
anyOf · anyOf[19] · object · $ref #/$defs/DeviceMessagesSendRequestBody
* messages · object
Station-local did_core_id -> device_id map. The authenticated addressed Station supplies the AccountId Station component; this body carries no cross-Station route and MUST NOT use ActorId JSON as a key.
anyOf · anyOf[20] · object · $ref #/$defs/DidOperationSubmitOutcome
* status · string (enum)
enum: "accepted" "duplicate" "pending"
* did · string · $ref ./common-ids.schema.json#/$defs/did
Canonical bare DID used for registration, DID method resolution and owner-published current resolution. It contains no path, query or fragment and MUST project through the registered method adapter to exactly one did_core_id.
pattern: ^did:[a-z0-9]+:[^\s/?#]+$
* accepted_at · string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
seq · integer
New method sequence number when available.
* operation_ref · string
Exact method-native immutable operation identifier. For did:webvh this is did + "?versionId=" + the submitted entry versionId. The authenticated response acknowledges the exact complete submitted operation, including proofs; accepted/duplicate MUST match the locally frozen typed request and its method-native version and sequence. A registry MUST NOT normalize or replace accepted entry bytes. A duplicate returns the original result for the same bytes.
receipts · array<object>
items · object
anyOf · anyOf[21] · object · $ref #/$defs/DidOperationSubmitRequestBody
* did · string · $ref ./common-ids.schema.json#/$defs/did
Canonical bare DID used for registration, DID method resolution and owner-published current resolution. It contains no path, query or fragment and MUST project through the registered method adapter to exactly one did_core_id.
pattern: ^did:[a-z0-9]+:[^\s/?#]+$
* did_method · string
DID method discriminator without the did: prefix (e.g. web, webvh, key). It MUST exactly equal the method component of did; verifiers dispatch method-specific validation only after that equality check.
pattern: ^[a-z0-9]+$
seq · integer
Optional method sequence number when the DID method exposes one.
prev_event_digest · string
Optional previous operation hash / key-log head, when required by the DID method.
pattern: ^sha256:[0-9a-f]{64}$
* operation · object
Complete DID method-native operation, including every controller/update/recovery proof required by that method. This is not a generic JSON Patch. The selected adapter MUST validate the immutable native operation and its full history before any state mutation; transport authentication never substitutes for method-native control proof.
anyOf · anyOf[22] · oneOf[2] · $ref #/$defs/DirectConversationFoundingAuthorityEvidence
Closed XOR authorization evidence for one Direct Conversation founding unit, matching the two registered ak.realm.create admission variants. The human branch feeds direct_conversation_genesis; the controller_agent branch feeds direct_conversation_agent_genesis. Carrying both, neither, or mixed branch fields rejects the whole unit.
oneOf · oneOf[0] · object
* kind · const "human"
enum: "human"
* contact_round_evidence · object · $ref ./contact-operations.schema.json#/$defs/contact_round_evidence_bundle
Portable evidence for the pair's current Contact round. The verifier re-derives founder from the root Contact round, never from the current round.
allOf · allOf[0] · …
recursion truncated at depth 8; see source schema for full shape
* contact_round_id · …
recursion truncated at depth 8; see source schema for full shape
previous_terminal_contact_round_id · …
recursion truncated at depth 8; see source schema for full shape
* contact_round · …
recursion truncated at depth 8; see source schema for full shape
* request_receipts · …
recursion truncated at depth 8; see source schema for full shape
normal_response_receipt · …
recursion truncated at depth 8; see source schema for full shape
glare_concurrency_attestations · …
recursion truncated at depth 8; see source schema for full shape
* current_proofs · …
recursion truncated at depth 8; see source schema for full shape
continuity_checkpoint · …
recursion truncated at depth 8; see source schema for full shape
* contact_round_continuity_chains · array<$ref ./contact-operations.schema.json#/$defs/contact_round_evidence_bundle>
Ordered tombstone/recontact predecessors from the current Contact round back to the pair's unique root Contact round, each linked by previous_terminal_contact_round_id. An empty array means the current round is itself the root. A break, a cycle, multiple roots or two directional proofs yielding different roots reject the unit.
items · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* kind · const "controller_agent"
enum: "controller_agent"
* agent_provision_ref · string · $ref ./principal-operations.schema.json#/$defs/event_id
Complete identity of the accepted Agent provision Event. Its digest is derived by decoding this suite-tagged full-digest EventId; no parallel agent_provision_digest is carried.
pattern: ^ak:event:[A-Za-z0-9_-]{44}$
* controller_binding_digest · string · $ref ./principal-operations.schema.json#/$defs/digest
pattern: ^sha256:[0-9a-f]{64}$
anyOf · anyOf[23] · object · $ref #/$defs/EventAdmissionSubmission
One exact producer-signed Event submitted to the current governance Station, plus the approval signatures required by a grant, Realm governance or List WIP policy for the Event action or for this registered submit operation. There are no RealmCommit, typed current result, offline-lease or proof-bundle sidecars. approval_signatures is the only sidecar and it is deliberately outside event: the Event bytes and event_id are finished before any approval is signed, so attaching them never changes the Event (zh/authz/constraint-schema.md section 9.2.5).
* event · object · $ref ./event-envelope.schema.json
Closed producer-signed Event. Shared persistent Events become final only when the current Realm governance Station issues a RealmCommit in the derived Realm, Circle, or Sidecar stream.
allOf · allOf[0] · ?
allOf · allOf[1] · ?
allOf · allOf[2] · ?
allOf · allOf[3] · ?
allOf · allOf[4] · ?
allOf · allOf[5] · $ref #/$defs/registered_admission_shape · $ref #/$defs/registered_admission_shape
allOf · allOf[6] · $ref #/$defs/registered_execution_shape · $ref #/$defs/registered_execution_shape
allOf · allOf[7] · ?
allOf · allOf[8] · ?
allOf · allOf[9] · ?
allOf · allOf[10] · ?
allOf · allOf[11] · ?
allOf · allOf[12] · ?
allOf · allOf[13] · ?
allOf · allOf[14] · ?
allOf · allOf[15] · ?
allOf · allOf[16] · ?
allOf · allOf[17] · ?
allOf · allOf[18] · ?
allOf · allOf[19] · ?
allOf · allOf[20] · ?
allOf · allOf[21] · ?
allOf · allOf[22] · ?
allOf · allOf[23] · ?
allOf · allOf[24] · ?
allOf · allOf[25] · ?
allOf · allOf[26] · ?
allOf · allOf[27] · ?
allOf · allOf[28] · ?
allOf · allOf[29] · ?
allOf · allOf[30] · ?
allOf · allOf[31] · ?
allOf · allOf[32] · ?
allOf · allOf[33] · ?
allOf · allOf[34] · ?
allOf · allOf[35] · ?
allOf · allOf[36] · ?
allOf · allOf[37] · ?
allOf · allOf[38] · ?
allOf · allOf[39] · ?
allOf · allOf[40] · ?
allOf · allOf[41] · ?
allOf · allOf[42] · ?
allOf · allOf[43] · ?
allOf · allOf[44] · ?
allOf · allOf[45] · ?
allOf · allOf[46] · ?
allOf · allOf[47] · ?
allOf · allOf[48] · ?
allOf · allOf[49] · ?
allOf · allOf[50] · ?
allOf · allOf[51] · ?
allOf · allOf[52] · ?
allOf · allOf[53] · ?
allOf · allOf[54] · ?
allOf · allOf[55] · ?
allOf · allOf[56] · ?
allOf · allOf[57] · ?
allOf · allOf[58] · ?
allOf · allOf[59] · ?
allOf · allOf[60] · ?
allOf · allOf[61] · ?
allOf · allOf[62] · ?
allOf · allOf[63] · ?
allOf · allOf[64] · ?
allOf · allOf[65] · ?
allOf · allOf[66] · ?
allOf · allOf[67] · ?
allOf · allOf[68] · ?
allOf · allOf[69] · ?
allOf · allOf[70] · ?
allOf · allOf[71] · ?
allOf · allOf[72] · ?
allOf · allOf[73] · ?
allOf · allOf[74] · ?
allOf · allOf[75] · ?
allOf · allOf[76] · ?
allOf · allOf[77] · ?
allOf · allOf[78] · ?
allOf · allOf[79] · ?
allOf · allOf[80] · ?
allOf · allOf[81] · ?
allOf · allOf[82] · ?
allOf · allOf[83] · ?
allOf · allOf[84] · ?
allOf · allOf[85] · ?
allOf · allOf[86] · ?
allOf · allOf[87] · ?
allOf · allOf[88] · ?
allOf · allOf[89] · ?
allOf · allOf[90] · ?
allOf · allOf[91] · ?
allOf · allOf[92] · ?
allOf · allOf[93] · ?
allOf · allOf[94] · ?
allOf · allOf[95] · ?
allOf · allOf[96] · ?
allOf · allOf[97] · ?
allOf · allOf[98] · ?
allOf · allOf[99] · ?
allOf · allOf[100] · ?
allOf · allOf[101] · ?
allOf · allOf[102] · ?
allOf · allOf[103] · ?
allOf · allOf[104] · ?
allOf · allOf[105] · ?
allOf · allOf[106] · ?
allOf · allOf[107] · ?
allOf · allOf[108] · ?
allOf · allOf[109] · ?
allOf · allOf[110] · ?
allOf · allOf[111] · ?
allOf · allOf[112] · ?
allOf · allOf[113] · ?
allOf · allOf[114] · ?
allOf · allOf[115] · ?
allOf · allOf[116] · ?
allOf · allOf[117] · ?
allOf · allOf[118] · ?
allOf · allOf[119] · ?
allOf · allOf[120] · ?
allOf · allOf[121] · ?
allOf · allOf[122] · ?
allOf · allOf[123] · ?
allOf · allOf[124] · ?
allOf · allOf[125] · ?
allOf · allOf[126] · ?
allOf · allOf[127] · ?
allOf · allOf[128] · ?
allOf · allOf[129] · ?
allOf · allOf[130] · ?
allOf · allOf[131] · ?
allOf · allOf[132] · ?
allOf · allOf[133] · ?
allOf · allOf[134] · ?
allOf · allOf[135] · ?
allOf · allOf[136] · ?
allOf · allOf[137] · ?
allOf · allOf[138] · ?
allOf · allOf[139] · ?
allOf · allOf[140] · ?
* event_id · string · $ref ./common-ids.schema.json#/$defs/event_id
Complete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern: ^ak:event:[A-Za-z0-9_-]{44}$
* kind · string
Standard ak.* Event kinds MUST appear in artifacts/registry/event-kind-registry.json. State convergence is defined by the registered pure reducer over kind + payload; producers do not submit typed current result writes.
pattern: ^ak\.[a-z0-9_]+(\.[a-z0-9_]+)*$
realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* scope_ref · $ref #/$defs/scope_ref · $ref #/$defs/scope_ref
Required producer-signed security scope. The closed union is ordinary existing realm, circle, or native sidecar scope plus the create-only realm_genesis exception. It enters proof.event_digest and E2EE AAD. Reducers independently derive the exact scope from schema-validated payload and accepted references; missing dependencies, nonexistent scope, realm_id mismatch, omitted sidecar_id, substituting circle for sidecar, or any unequal field is fail closed. Sidecar domain Event kinds remain Extension-owned; recognizing this native security shape does not make Kernel interpret the Sidecar reducer. Exact product targets remain inside recipient-visible ciphertext.
* actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · …
recursion truncated at depth 8; see source schema for full shape
executed_by · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · …
recursion truncated at depth 8; see source schema for full shape
authorization_ref · oneOf[6]
Optional. Required when executed_by is present. It identifies an accepted Grant, delegation Event, DID-document delegation, or one of the closed profile-specific authority constants. The current governance Station evaluates the reference against the target stream's committed state.
oneOf · oneOf[0] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[2] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[3] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[4] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[5] · …
recursion truncated at depth 8; see source schema for full shape
applet_id · $ref #/$defs/applet_id · $ref #/$defs/applet_id
Optional signed Applet provenance. Required by ak.profile.applet_* when the Event is introduced by an Applet, Ghost Actor, bridge, or delegated applet path. Enters canonical event bytes and therefore is covered by proof.event_digest. When present, authorization_ref MUST also be present and resolve to a real active registration/capability grant binding this applet_id, registration_epoch, action and resource per zh/extensions/applet-integration.md sections 4, 8 and 11. Service-actor self-signature proves provenance but is not an authorization substitute. Capability-gated actions require a grant covering action/resource. For subject_only operations the referenced grant binds only the exact active install and cannot replace the subject signature, FSM or independent action authority. Service self-authored Events use ActorId.service; the install grant subject MUST be the same exact ActorId.service as its producer; hosting Station and effective scope are verified separately without coercing a Service into an account variant.
external_ref · $ref #/$defs/external_ref · $ref #/$defs/external_ref
Optional signed external provenance reference for Applet / bridge-originated Events. It is covered by event_digest and MUST NOT be carried only in unsigned when used for loop prevention, audit, or external-message idempotency. Must not contain unauthorized external plaintext.
* created_at · $ref #/$defs/canonical_event_timestamp · $ref #/$defs/canonical_event_timestamp
semantic_refs · array<$ref #/$defs/semantic_ref>
Optional semantic refs with role. Omit when there are no semantic references; an explicitly empty array is not canonical. Admission selectors determine any required references. PCR policy recovery has no DID-root anchor reference; its policy/session/replacement-key authority is verified separately.
items · …
recursion truncated at depth 8; see source schema for full shape
* payload · object
* producer_proof · $ref #/$defs/event_proof · $ref #/$defs/event_proof
The Event's sole portable producer proof. Storage receipts are separate objects and never authorize this Event. producer_proof and unsigned remain outside the canonical Event digest. Exact retries preserve the verified producer proof.
approval_signatures · array<$ref ./approval-signature.schema.json>
One ak.schema.approval_signature.v1 object per approver. An event-target signature binds approval_target.event_id equal to event.event_id. An operation-target signature is allowed only when capability-action-registry.json resolves its action to this exact carrier operation and binds request_canonical_digest to the original typed request with approval_signatures omitted. Every ingress that wraps EventAdmissionSubmission -- ordinary self submit, batch submission, control transactions, facade hand-off -- reuses this one field and MUST NOT define its own DTO. The array is omitted when no approval layer demands evidence; it MUST NOT be present and empty. The governance Station persists the evidence, the verification basis, the nonce consumption and the binding to this submission inside the same atomic acceptance transaction, and the shared Realm Event store keeps the original Event bytes unchanged.
items · object · $ref ./approval-signature.schema.json
The single approval evidence type of v1 (zh/authz/constraint-schema.md section 9.2). One approver signs one exact target: either a fully authored Event that has not been submitted yet, or the original typed RequestBody of one operation whose evidence carrier is registered in capability-action-registry.json. The object is not an Event, never enters Realm history, and MUST NOT be written into an EventEnvelope, a signed payload or an Event semantic_refs[] entry. It travels in the carrier registered for the approved action. It proves that an approver approved that target; it proves nothing about the initiator's own authority.
* input · …
recursion truncated at depth 8; see source schema for full shape
* proof · …
recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[24] · object · $ref #/$defs/EventDeliveryStatusOutcome
Complete frozen target set for one visible Event. Rows are sorted byte-wise by unique opaque target_id. Consumers derive the pending count by counting pending_route and pending_delivery rows, and derive aggregate state as pending iff that count is non-zero.
* event_id · string · $ref #/$defs/EventId
pattern: ^ak:event:[A-Za-z0-9_-]{44}$
* targets · array<$ref #/$defs/EventDeliveryTargetStatus>
items · object · $ref #/$defs/EventDeliveryTargetStatus
Authorized projection of one frozen Realm fanout target. target_id is opaque and stable. service_id is present only when the caller can currently read at least one exact joined-member ActorId that contributed the target.
* target_id · …
recursion truncated at depth 8; see source schema for full shape
* status · …
recursion truncated at depth 8; see source schema for full shape
service_id · …
recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[25] · object · $ref #/$defs/EventDeliveryStatusRequestBody
Authenticated, non-enumerating request for the durable fanout state of one caller-visible accepted Event.
* event_id · string · $ref #/$defs/EventId
pattern: ^ak:event:[A-Za-z0-9_-]{44}$
anyOf · anyOf[26] · object · $ref #/$defs/EventSubmitEnvelope
Closed producer-signed Event. Shared persistent Events become final only when the current Realm governance Station issues a RealmCommit in the derived Realm, Circle, or Sidecar stream.
allOf · allOf[0] · ?
allOf · allOf[1] · ?
allOf · allOf[2] · ?
allOf · allOf[3] · ?
allOf · allOf[4] · ?
allOf · allOf[5] · $ref #/$defs/registered_admission_shape · $ref #/$defs/registered_admission_shape
allOf · allOf[6] · $ref #/$defs/registered_execution_shape · $ref #/$defs/registered_execution_shape
allOf · allOf[7] · ?
allOf · allOf[8] · ?
allOf · allOf[9] · ?
allOf · allOf[10] · ?
allOf · allOf[11] · ?
allOf · allOf[12] · ?
allOf · allOf[13] · ?
allOf · allOf[14] · ?
allOf · allOf[15] · ?
allOf · allOf[16] · ?
allOf · allOf[17] · ?
allOf · allOf[18] · ?
allOf · allOf[19] · ?
allOf · allOf[20] · ?
allOf · allOf[21] · ?
allOf · allOf[22] · ?
allOf · allOf[23] · ?
allOf · allOf[24] · ?
allOf · allOf[25] · ?
allOf · allOf[26] · ?
allOf · allOf[27] · ?
allOf · allOf[28] · ?
allOf · allOf[29] · ?
allOf · allOf[30] · ?
allOf · allOf[31] · ?
allOf · allOf[32] · ?
allOf · allOf[33] · ?
allOf · allOf[34] · ?
allOf · allOf[35] · ?
allOf · allOf[36] · ?
allOf · allOf[37] · ?
allOf · allOf[38] · ?
allOf · allOf[39] · ?
allOf · allOf[40] · ?
allOf · allOf[41] · ?
allOf · allOf[42] · ?
allOf · allOf[43] · ?
allOf · allOf[44] · ?
allOf · allOf[45] · ?
allOf · allOf[46] · ?
allOf · allOf[47] · ?
allOf · allOf[48] · ?
allOf · allOf[49] · ?
allOf · allOf[50] · ?
allOf · allOf[51] · ?
allOf · allOf[52] · ?
allOf · allOf[53] · ?
allOf · allOf[54] · ?
allOf · allOf[55] · ?
allOf · allOf[56] · ?
allOf · allOf[57] · ?
allOf · allOf[58] · ?
allOf · allOf[59] · ?
allOf · allOf[60] · ?
allOf · allOf[61] · ?
allOf · allOf[62] · ?
allOf · allOf[63] · ?
allOf · allOf[64] · ?
allOf · allOf[65] · ?
allOf · allOf[66] · ?
allOf · allOf[67] · ?
allOf · allOf[68] · ?
allOf · allOf[69] · ?
allOf · allOf[70] · ?
allOf · allOf[71] · ?
allOf · allOf[72] · ?
allOf · allOf[73] · ?
allOf · allOf[74] · ?
allOf · allOf[75] · ?
allOf · allOf[76] · ?
allOf · allOf[77] · ?
allOf · allOf[78] · ?
allOf · allOf[79] · ?
allOf · allOf[80] · ?
allOf · allOf[81] · ?
allOf · allOf[82] · ?
allOf · allOf[83] · ?
allOf · allOf[84] · ?
allOf · allOf[85] · ?
allOf · allOf[86] · ?
allOf · allOf[87] · ?
allOf · allOf[88] · ?
allOf · allOf[89] · ?
allOf · allOf[90] · ?
allOf · allOf[91] · ?
allOf · allOf[92] · ?
allOf · allOf[93] · ?
allOf · allOf[94] · ?
allOf · allOf[95] · ?
allOf · allOf[96] · ?
allOf · allOf[97] · ?
allOf · allOf[98] · ?
allOf · allOf[99] · ?
allOf · allOf[100] · ?
allOf · allOf[101] · ?
allOf · allOf[102] · ?
allOf · allOf[103] · ?
allOf · allOf[104] · ?
allOf · allOf[105] · ?
allOf · allOf[106] · ?
allOf · allOf[107] · ?
allOf · allOf[108] · ?
allOf · allOf[109] · ?
allOf · allOf[110] · ?
allOf · allOf[111] · ?
allOf · allOf[112] · ?
allOf · allOf[113] · ?
allOf · allOf[114] · ?
allOf · allOf[115] · ?
allOf · allOf[116] · ?
allOf · allOf[117] · ?
allOf · allOf[118] · ?
allOf · allOf[119] · ?
allOf · allOf[120] · ?
allOf · allOf[121] · ?
allOf · allOf[122] · ?
allOf · allOf[123] · ?
allOf · allOf[124] · ?
allOf · allOf[125] · ?
allOf · allOf[126] · ?
allOf · allOf[127] · ?
allOf · allOf[128] · ?
allOf · allOf[129] · ?
allOf · allOf[130] · ?
allOf · allOf[131] · ?
allOf · allOf[132] · ?
allOf · allOf[133] · ?
allOf · allOf[134] · ?
allOf · allOf[135] · ?
allOf · allOf[136] · ?
allOf · allOf[137] · ?
allOf · allOf[138] · ?
allOf · allOf[139] · ?
allOf · allOf[140] · ?
* event_id · string · $ref ./common-ids.schema.json#/$defs/event_id
Complete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern: ^ak:event:[A-Za-z0-9_-]{44}$
* kind · string
Standard ak.* Event kinds MUST appear in artifacts/registry/event-kind-registry.json. State convergence is defined by the registered pure reducer over kind + payload; producers do not submit typed current result writes.
pattern: ^ak\.[a-z0-9_]+(\.[a-z0-9_]+)*$
realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* scope_ref · $ref #/$defs/scope_ref · $ref #/$defs/scope_ref
Required producer-signed security scope. The closed union is ordinary existing realm, circle, or native sidecar scope plus the create-only realm_genesis exception. It enters proof.event_digest and E2EE AAD. Reducers independently derive the exact scope from schema-validated payload and accepted references; missing dependencies, nonexistent scope, realm_id mismatch, omitted sidecar_id, substituting circle for sidecar, or any unequal field is fail closed. Sidecar domain Event kinds remain Extension-owned; recognizing this native security shape does not make Kernel interpret the Sidecar reducer. Exact product targets remain inside recipient-visible ciphertext.
* actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind · …
recursion truncated at depth 8; see source schema for full shape
* account_id · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* kind · …
recursion truncated at depth 8; see source schema for full shape
* service_id · …
recursion truncated at depth 8; see source schema for full shape
executed_by · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind · …
recursion truncated at depth 8; see source schema for full shape
* account_id · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* kind · …
recursion truncated at depth 8; see source schema for full shape
* service_id · …
recursion truncated at depth 8; see source schema for full shape
authorization_ref · oneOf[6]
Optional. Required when executed_by is present. It identifies an accepted Grant, delegation Event, DID-document delegation, or one of the closed profile-specific authority constants. The current governance Station evaluates the reference against the target stream's committed state.
oneOf · oneOf[0] · $ref #/$defs/grant_ref · $ref #/$defs/grant_ref
oneOf · oneOf[1] · $ref #/$defs/event_ref · $ref #/$defs/event_ref
oneOf · oneOf[2] · $ref #/$defs/did_delegation_ref · $ref #/$defs/did_delegation_ref
oneOf · oneOf[3] · $ref #/$defs/direct_conversation_participant_authority_ref · $ref #/$defs/direct_conversation_participant_authority_ref
oneOf · oneOf[4] · $ref #/$defs/direct_conversation_bootstrap_authority_ref · $ref #/$defs/direct_conversation_bootstrap_authority_ref
oneOf · oneOf[5] · $ref #/$defs/membership_compensation_delegation_ref · $ref #/$defs/membership_compensation_delegation_ref
applet_id · $ref #/$defs/applet_id · $ref #/$defs/applet_id
Optional signed Applet provenance. Required by ak.profile.applet_* when the Event is introduced by an Applet, Ghost Actor, bridge, or delegated applet path. Enters canonical event bytes and therefore is covered by proof.event_digest. When present, authorization_ref MUST also be present and resolve to a real active registration/capability grant binding this applet_id, registration_epoch, action and resource per zh/extensions/applet-integration.md sections 4, 8 and 11. Service-actor self-signature proves provenance but is not an authorization substitute. Capability-gated actions require a grant covering action/resource. For subject_only operations the referenced grant binds only the exact active install and cannot replace the subject signature, FSM or independent action authority. Service self-authored Events use ActorId.service; the install grant subject MUST be the same exact ActorId.service as its producer; hosting Station and effective scope are verified separately without coercing a Service into an account variant.
external_ref · $ref #/$defs/external_ref · $ref #/$defs/external_ref
Optional signed external provenance reference for Applet / bridge-originated Events. It is covered by event_digest and MUST NOT be carried only in unsigned when used for loop prevention, audit, or external-message idempotency. Must not contain unauthorized external plaintext.
* created_at · $ref #/$defs/canonical_event_timestamp · $ref #/$defs/canonical_event_timestamp
semantic_refs · array<$ref #/$defs/semantic_ref>
Optional semantic refs with role. Omit when there are no semantic references; an explicitly empty array is not canonical. Admission selectors determine any required references. PCR policy recovery has no DID-root anchor reference; its policy/session/replacement-key authority is verified separately.
items · $ref #/$defs/semantic_ref · $ref #/$defs/semantic_ref
* payload · object
* producer_proof · $ref #/$defs/event_proof · $ref #/$defs/event_proof
The Event's sole portable producer proof. Storage receipts are separate objects and never authorize this Event. producer_proof and unsigned remain outside the canonical Event digest. Exact retries preserve the verified producer proof.
anyOf · anyOf[27] · object · $ref #/$defs/EventsSubmitBatchRequestBody
Legacy-named typed array retained only as the nested prepared_event_unit request in security-transaction.schema.json. It is not an ak.self.events.command.submit.v1 request: that operation accepts only authority-commit-operations.schema.json#/$defs/self_submit_request, including its closed ordinary_realm_bootstrap branch. The parent security transaction fixes the recovery unit type, slot count, order and authorization; this array alone grants no generic Event batch admission.
* events · array<$ref #/$defs/EventAdmissionSubmission>
items · object · $ref #/$defs/EventAdmissionSubmission
One exact producer-signed Event submitted to the current governance Station, plus the approval signatures required by a grant, Realm governance or List WIP policy for the Event action or for this registered submit operation. There are no RealmCommit, typed current result, offline-lease or proof-bundle sidecars. approval_signatures is the only sidecar and it is deliberately outside event: the Event bytes and event_id are finished before any approval is signed, so attaching them never changes the Event (zh/authz/constraint-schema.md section 9.2.5).
* event · …
recursion truncated at depth 8; see source schema for full shape
approval_signatures · …
recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[28] · object · $ref #/$defs/GrantList
Atomic subject-visible snapshot of active effective grants. Each row carries its own exact current-result revision; state_digest authenticates the list as a whole and is never a per-grant CAS operand.
* grants · array<$ref #/$defs/EffectiveCapabilityGrantRow>
items · object · $ref #/$defs/EffectiveCapabilityGrantRow
One active effective capability grant and the exact revision of that same capability_grant current result, read atomically by the governing Station. This revision is the only valid authoring basis for a subject-signed ak.capability.relinquish Event; state_digest, evaluated_at, Event ids and locally folded history MUST NOT substitute for it.
* grant · …
recursion truncated at depth 8; see source schema for full shape
* revision · …
recursion truncated at depth 8; see source schema for full shape
* state_digest · string
Digest of the complete effective-list snapshot. It MUST NOT be copied into expected_revision or otherwise treated as one grant's revision.
pattern: ^(sha256|blake3):[0-9a-f]{64}$
* evaluated_at · string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
anyOf · anyOf[29] · object · $ref #/$defs/IdentityDocumentView
Result of ak.root.identity.document.resource.get.v1 — current DID Document plus normalized view hints.
* did_document · object
Raw DID Core document with W3C field names preserved.
normalized_view · object
Optional Arkret normalized principal view (snake_case) — derived projection only, NOT a re-publishable DID Document. See zh/identity/identity-did.md §6.
method_evidence · oneOf[3] · $ref ./identity-resolution.schema.json#/$defs/method_history_evidence
Adapter-routed evidence. evidence_kind is the single-source discriminator: the receiver resolves it through did-method-adapter-registry.json method_evidence_kind, which is unique across active adapters, to exactly one active adapter for this versioned schema. The evidence carries no adapter_version; an adapter change requires a new schema/operation version rather than a registry drift under the same wire shape. Unknown evidence kinds fail closed.
oneOf · oneOf[0] · $ref #/$defs/webvh_method_history_evidence · $ref #/$defs/webvh_method_history_evidence
oneOf · oneOf[1] · $ref #/$defs/did_web_method_history_evidence · $ref #/$defs/did_web_method_history_evidence
oneOf · oneOf[2] · $ref #/$defs/did_key_method_history_evidence · $ref #/$defs/did_key_method_history_evidence
cached_at · string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
anyOf · anyOf[30] · object · $ref #/$defs/IdentityLogListOutcome
Result of ak.root.identity.log.read.list.v1. Entries are returned in the DID method's own native log form: for did:webvh each entry is a verbatim did.jsonl log entry with its native versionId, entryHash chain and Data Integrity proof. Arkret defines no parallel entry envelope, sequence numbering, hash chain or proof transcript over DID logs — the method already provides all of them, and a second signed representation of the same history could disagree with the first. Methods without a native history (did:web) MUST report that rather than being wrapped in a shape that implies one.
* did · string · $ref ./common-ids.schema.json#/$defs/did
Canonical bare DID used for registration, DID method resolution and owner-published current resolution. It contains no path, query or fragment and MUST project through the registered method adapter to exactly one did_core_id.
pattern: ^did:[a-z0-9]+:[^\s/?#]+$
* method · string
DID method of the returned log, e.g. did:webvh. Consumers dispatch parsing and verification on this value.
native_history · boolean
False when the method has no native key history at all (did:web). Such a response MUST return an empty entries array; the server MUST NOT synthesise entries, sequence numbers or a chain the method does not have.
* entries · array<object>
Verbatim method-native log entries in method order. Arkret does not reinterpret, renumber or re-sign them; verification follows the method specification.
items · object
next_cursor · string
Opaque continuation cursor for the next page when has_more=true.
* has_more · boolean
anyOf · anyOf[31] · object · $ref #/$defs/IdentityReceiptListOutcome
Result of ak.root.identity.receipts.read.list.v1. receipts[] is a tagged union over two distinct object families discriminated by their schema constant: ak.schema.identity_receipt.v1 records a role inside a DID registry consensus group (writer / witness / replica) and binds seq + accepted_entry_digest, while ak.schema.did_webvh_witness_receipt.v1 records a did:webvh method witness observed at a specific versionId. The two say different things with the same English word, so the discriminator is mandatory and a verifier MUST branch on it rather than infer intent from which optional fields happen to be present.
* receipts · array<oneOf[2]>
items · oneOf[2]
oneOf · oneOf[0] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · …
recursion truncated at depth 8; see source schema for full shape
threshold_met · boolean
True when the returned receipt set satisfies the effective witness threshold for the requested head. The effective threshold is the strictest intersection of the method-native parameters.witness.threshold and the deployment / Realm policy minimum (identity-did.md §3.4.2), and distinctness is counted over controlling_organization_did where policy requires distinct organizations. Omitted when the registry cannot evaluate threshold policy for this query; an omitted value MUST NOT be read as true. A true value is an Arkret-layer convenience and MUST NOT replace verifying the standard did-witness.json proofs.
anyOf · anyOf[32] · object · $ref #/$defs/IdentityResolveOutcome
did_document · object
key_log_head · string · $ref ./account-operations.schema.json#/$defs/digest
pattern: ^(sha256|blake3):[0-9a-f]{64}$
seq · integer
method_evidence · oneOf[1] · $ref #/$defs/IdentityMethodEvidence
oneOf · oneOf[0] · object · $ref #/$defs/DidWebvhIdentityMethodEvidence
Method-native pins derived only after fail-closed verification of the complete did:webvh history. control_key_digest is SHA-256 over the decoded canonical multikey bytes of parameters.updateKeys[0] at version_id.
* kind · …
recursion truncated at depth 8; see source schema for full shape
* version_id · …
recursion truncated at depth 8; see source schema for full shape
* control_key_digest · …
recursion truncated at depth 8; see source schema for full shape
receipts · array<$ref ./identity-receipt.schema.json>
items · object · $ref ./identity-receipt.schema.json
* schema · …
recursion truncated at depth 8; see source schema for full shape
* receipt_id · …
recursion truncated at depth 8; see source schema for full shape
* subject_did · …
recursion truncated at depth 8; see source schema for full shape
* seq · …
recursion truncated at depth 8; see source schema for full shape
* accepted_entry_digest · …
recursion truncated at depth 8; see source schema for full shape
* registry_id · …
recursion truncated at depth 8; see source schema for full shape
* witness_role · …
recursion truncated at depth 8; see source schema for full shape
audience · …
recursion truncated at depth 8; see source schema for full shape
* created_at · …
recursion truncated at depth 8; see source schema for full shape
* signature · …
recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[33] · object · $ref #/$defs/IdentityResolveRequestBody
* did · string · $ref ./common-ids.schema.json#/$defs/did
Canonical bare DID used for registration, DID method resolution and owner-published current resolution. It contains no path, query or fragment and MUST project through the registered method adapter to exactly one did_core_id.
pattern: ^did:[a-z0-9]+:[^\s/?#]+$
requested_evidence_kinds · array<string (enum)>
items · string (enum)
enum: "did_webvh"
anyOf · anyOf[34] · object · $ref #/$defs/InitialSessionGrantIntent
Initial Standard SessionGrant intent embedded in identity_creation registration. It reuses the DPoP holder key established by account handoff; Account Authority recomputes RFC 7638 thumbprint of session_public_key and requires equality with the handoff/control-proof dpop_jkt. It is not a separate authorization or credential.
* device_id · string · $ref ./common-ids.schema.json#/$defs/device_id
pattern: ^ak:device:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$
* session_public_key · string (canonical-public-jwk-jcs) · format=canonical-public-jwk-jcs
Exact RFC 8785 JCS public JWK for the existing handoff DPoP holder key. Private members are forbidden.
* audience_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
anyOf · anyOf[35] · object · $ref #/$defs/MlsGroupStateMaterialOutcome
Exact RFC 9420 public group-state material. *_bytes_b64 use unpadded base64url. Consumers MUST decode each content-addressed Blob ref's embedded suite, hash the raw bytes under that suite, compare the digest, verify GroupInfo and ratchet_tree consistency, then derive leaf_index only from occupied leaves in the verified tree. Blob suites are independent of the fixed SHA-256 Event/RealmCommit identity suite.
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* effective_scope · oneOf[3] · $ref ./event-payload.schema.json#/$defs/effective_scope
oneOf · oneOf[0] · object
* kind · …
recursion truncated at depth 8; see source schema for full shape
* realm_id · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* kind · …
recursion truncated at depth 8; see source schema for full shape
* realm_id · …
recursion truncated at depth 8; see source schema for full shape
* circle_id · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[2] · object
* kind · …
recursion truncated at depth 8; see source schema for full shape
* realm_id · …
recursion truncated at depth 8; see source schema for full shape
* sidecar_id · …
recursion truncated at depth 8; see source schema for full shape
* mls_group_id · string · $ref ./common-ids.schema.json#/$defs/mls_group_id
RFC 9420 group_id as base64url_no_pad(SHA-256(UTF8("ak.mls.group_id.v1") || 0x00 || canonical_effective_scope_key_bytes(effective_scope))), so exactly 43 characters. Derived by the reducer and the SDK from the effective scope alone; actors never submit it. The v1 formula is the only one: the earlier reversible base64url of the scope key bytes MUST NOT be accepted alongside it. See zh/models/realm-and-space.md section 2.2.
pattern: ^[A-Za-z0-9_-]{43}$
* epoch · const 0
enum: 0
* group_state_event_id · string · $ref #/$defs/EventId
pattern: ^ak:event:[A-Za-z0-9_-]{44}$
* group_info_ref · string
Copied byte-for-byte from the accepted ak.mls.genesis payload; the embedded Blob digest suite is the sole wire carrier of the material digest and is independent of the fixed SHA-256 Event/RealmCommit identity suite (encoding.md 4.0.1).
pattern: ^ak:blob:(?:sha256|blake3):[0-9a-f]{64}$
* group_info_bytes_b64 · string
pattern: ^[A-Za-z0-9_-]+$
* ratchet_tree_ref · string
Copied byte-for-byte from the accepted ak.mls.genesis payload; the embedded Blob digest suite is the sole wire carrier of the material digest and is independent of the fixed SHA-256 Event/RealmCommit identity suite (encoding.md 4.0.1).
pattern: ^ak:blob:(?:sha256|blake3):[0-9a-f]{64}$
* ratchet_tree_bytes_b64 · string
pattern: ^[A-Za-z0-9_-]+$
anyOf · anyOf[36] · object · $ref #/$defs/MlsGroupStateMaterialRequestBody
Read-only service request for the exact public MLS epoch-0 GroupInfo and ratchet_tree bytes committed by one accepted ak.mls.genesis Event. Every Genesis selector is copied from that Event. When caller_actor_id is present, target_commit_event_ref and target_epoch are mandatory; governance checks current and target-cut member/history authority and source Station replication right at the target accepted Commit cut. Without caller_actor_id this remains the original Station replication-only read, with source Station replication right checked at the Genesis Commit position.
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* effective_scope · oneOf[3] · $ref ./event-payload.schema.json#/$defs/effective_scope
oneOf · oneOf[0] · object
* kind · …
recursion truncated at depth 8; see source schema for full shape
* realm_id · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* kind · …
recursion truncated at depth 8; see source schema for full shape
* realm_id · …
recursion truncated at depth 8; see source schema for full shape
* circle_id · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[2] · object
* kind · …
recursion truncated at depth 8; see source schema for full shape
* realm_id · …
recursion truncated at depth 8; see source schema for full shape
* sidecar_id · …
recursion truncated at depth 8; see source schema for full shape
* mls_group_id · string · $ref ./common-ids.schema.json#/$defs/mls_group_id
RFC 9420 group_id as base64url_no_pad(SHA-256(UTF8("ak.mls.group_id.v1") || 0x00 || canonical_effective_scope_key_bytes(effective_scope))), so exactly 43 characters. Derived by the reducer and the SDK from the effective scope alone; actors never submit it. The v1 formula is the only one: the earlier reversible base64url of the scope key bytes MUST NOT be accepted alongside it. See zh/models/realm-and-space.md section 2.2.
pattern: ^[A-Za-z0-9_-]{43}$
* epoch · const 0
enum: 0
* group_state_event_id · string · $ref #/$defs/EventId
pattern: ^ak:event:[A-Za-z0-9_-]{44}$
caller_actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind · …
recursion truncated at depth 8; see source schema for full shape
* account_id · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* kind · …
recursion truncated at depth 8; see source schema for full shape
* service_id · …
recursion truncated at depth 8; see source schema for full shape
target_commit_event_ref · string · $ref #/$defs/EventId
pattern: ^ak:event:[A-Za-z0-9_-]{44}$
target_epoch · integer
* group_info_ref · string
Copied byte-for-byte from the accepted ak.mls.genesis payload; the embedded Blob digest suite is the sole wire carrier of the material digest and is independent of the fixed SHA-256 Event/RealmCommit identity suite (encoding.md 4.0.1).
pattern: ^ak:blob:(?:sha256|blake3):[0-9a-f]{64}$
* ratchet_tree_ref · string
Copied byte-for-byte from the accepted ak.mls.genesis payload; the embedded Blob digest suite is the sole wire carrier of the material digest and is independent of the fixed SHA-256 Event/RealmCommit identity suite (encoding.md 4.0.1).
pattern: ^ak:blob:(?:sha256|blake3):[0-9a-f]{64}$
max_response_bytes · integer
example: 8388608
anyOf · anyOf[37] · object · $ref #/$defs/ModerationReportOutcome
* report_id · string
pattern: ^ak:report:[A-Za-z0-9_-]{44}$
routed_to_ids · array<$ref ./common-ids.schema.json#/$defs/did_core_id>
Stable core_ids selected as moderation routing destinations. MUST be omitted for an ordinary reporter and MAY be serialized only when the caller independently holds moderation/governance capability for the report's exact scope. Endpoint discovery and DID verification remain separate resolution steps.
items · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
anyOf · anyOf[38] · object · $ref #/$defs/OrganizationRegistrationChallenge
Single-use control challenge. Every binding field exists to close one replay path: purpose separates this proof from any other signature the organization makes, audience and trust_domain pin it to this deployment, origin pins the HTTP surface, nonce makes it unrepeatable, and the expiry window bounds how long a captured proof stays useful. A registry MUST consume the challenge on the first successful use and atomically persist (challenge_id, canonical_request_digest, outcome). Only a byte-identical retry may return that stored outcome; the same challenge with any different digest is invalid.
* challenge_id · string
pattern: ^ak:organization_registration_challenge:[0-9a-f]{64}$
* organization_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* organization_did · string · $ref ./common-ids.schema.json#/$defs/did
Canonical bare DID used for registration, DID method resolution and owner-published current resolution. It contains no path, query or fragment and MUST project through the registered method adapter to exactly one did_core_id.
pattern: ^did:[a-z0-9]+:[^\s/?#]+$
* purpose · const "ak.organization_registration_control_proof.v1"
Fixed purpose tag, identical to the signing context of OrganizationControlProof.proofs[]. A proof produced for any other purpose MUST NOT verify here.
enum: "ak.organization_registration_control_proof.v1"
* nonce · string
pattern: ^[A-Za-z0-9_-]{22,128}$
* audience_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* origin · string (uri) · format=uri · $ref ./common-ids.schema.json#/$defs/web_origin
Canonical HTTP(S) Web Origin: lowercase scheme/host plus an optional valid non-default effective port. Userinfo, path (including a trailing slash), query, fragment, explicit :80 on HTTP, and explicit :443 on HTTPS are forbidden.
pattern: ^(?:http://(?:\[[0-9A-Fa-f:.]+\]|[a-z0-9](?:[a-z0-9.-]*[a-z0-9])?)(?::(?!80$)(?:[1-9]|[1-9][0-9]{1,3}|[1-5][0-9]{4}|6[0-4][0-9]{3}|65[0-4][0-9]{2}|655[0-2][0-9]|6553[0-5]))?|https://(?:\[[0-9A-Fa-f:.]+\]|[a-z0-9](?:[a-z0-9.-]*[a-z0-9])?)(?::(?!443$)(?:[1-9]|[1-9][0-9]{1,3}|[1-5][0-9]{4}|6[0-4][0-9]{3}|65[0-4][0-9]{2}|655[0-2][0-9]|6553[0-5]))?)$
* trust_domain · string · $ref ./common-ids.schema.json#/$defs/trust_domain
pattern: ^ak:trust_domain:[a-z0-9][a-z0-9._\-:]{0,127}$
* local_admin_subject_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* requested_scopes · array<$ref #/$defs/OrganizationRegistrationScope>
items · string (enum) · $ref #/$defs/OrganizationRegistrationScope
Closed set of local administrative scopes a registration may delegate. organization_profile_manage covers this deployment's local organization profile and display; organization_realm_endorse permits issuing ak.realm.organization statements on the organization's behalf; organization_service_delegate permits declaring organization-to-service delegations locally. The set is closed because an open scope vocabulary would let a deployment mint authority the organization never consented to. Holding a scope is a permission to act later, not an action: registration by itself creates no Realm, membership, governance-Station authority, capability or service delegation.
enum: "organization_profile_manage" "organization_realm_endorse" "organization_service_delegate"
* expires_at · string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
* created_at · string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
anyOf · anyOf[39] · object · $ref #/$defs/OrganizationRegistrationChallengeRequestBody
Request a single-use control challenge for an external Organization DID. Two phases are mandatory: the registry issues the challenge and remembers it, then the caller proves control against it. Folding this into ensure would let the caller supply its own challenge, at which point neither freshness nor single use can be established by the receiver.
* organization_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* organization_did · string · $ref ./common-ids.schema.json#/$defs/did
Canonical bare DID used for registration, DID method resolution and owner-published current resolution. It contains no path, query or fragment and MUST project through the registered method adapter to exactly one did_core_id.
pattern: ^did:[a-z0-9]+:[^\s/?#]+$
* local_admin_subject_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* requested_scopes · array<$ref #/$defs/OrganizationRegistrationScope>
items · string (enum) · $ref #/$defs/OrganizationRegistrationScope
Closed set of local administrative scopes a registration may delegate. organization_profile_manage covers this deployment's local organization profile and display; organization_realm_endorse permits issuing ak.realm.organization statements on the organization's behalf; organization_service_delegate permits declaring organization-to-service delegations locally. The set is closed because an open scope vocabulary would let a deployment mint authority the organization never consented to. Holding a scope is a permission to act later, not an action: registration by itself creates no Realm, membership, governance-Station authority, capability or service delegation.
enum: "organization_profile_manage" "organization_realm_endorse" "organization_service_delegate"
anyOf · anyOf[40] · object · $ref #/$defs/OrganizationRegistrationEnsureRequestBody
Register an external Organization identity with this deployment by submitting both its stable organization_id core and current published organization_did. Idempotent on organization_id: replaying the same registration returns the existing binding with created=false. This operation registers a reference and a local administrative binding; it does not host the DID's method history, does not make this deployment its controller, and does not create Realm state.
* organization_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* organization_did · string · $ref ./common-ids.schema.json#/$defs/did
Canonical bare DID used for registration, DID method resolution and owner-published current resolution. It contains no path, query or fragment and MUST project through the registered method adapter to exactly one did_core_id.
pattern: ^did:[a-z0-9]+:[^\s/?#]+$
* challenge_id · string
pattern: ^ak:organization_registration_challenge:[0-9a-f]{64}$
* version_id · string
The exact resolved DID version the control proof was made against. Pinning the version is what makes the receipt auditable later: without it, a receipt asserts control at an unknown point in the DID's history.
pattern: ^(?!ak:)
* log_head_digest · string
pattern: ^sha256:[0-9a-f]{64}$
* control_proof · object · $ref #/$defs/OrganizationControlProof
Method-native proof that the caller controls the external Organization DID at the pinned version. proof_kind is a closed discriminator with exactly two members, both of which describe a MATURE, already-published DID. Creating a new Organization DID is a separate inception / governance ceremony and deliberately has no member here: a receiver must never have to guess whether a proof asserts control of existing state or creation of new state. This object never carries an Arkret-issued challenge signature in place of method-native control evidence.
allOf · allOf[0] · ?
* proof_kind · string (enum)
resolved_verification_method: a single signature by a verification method that is in the organization DID's control relationship at version_id. governance_quorum: a threshold of signatures from the organization's governance key set. Witness attestation is neither of these and MUST NOT be substituted for control evidence (identity-did.md §8.1).
enum: "resolved_verification_method" "governance_quorum"
quorum_threshold · integer
Required when proof_kind=governance_quorum and forbidden otherwise. The number of distinct valid governance signatures the organization's own policy demands. proofs[] MUST contain at least this many entries signed by distinct verification methods; JSON Schema cannot compare the two, so the receiver MUST enforce it and fail closed when short.
* proofs · array<$ref ./event-envelope.schema.json#/$defs/proof>
Detached proofs over canonical_json({context:'ak.organization_registration_control_proof.v1', challenge_id, organization_id, organization_did, local_admin_subject, version_id, log_head_digest, verification_method, created_at}). The verifier independently validates the published organization_did and requires project(organization_did)=organization_id before checking the DID URL verification_method. Binding the challenge, stable core, DID, beneficiary admin and exact version together prevents replay across deployments, resolutions or beneficiaries.
items · …
recursion truncated at depth 8; see source schema for full shape
* local_admin_subject_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* requested_scopes · array<$ref #/$defs/OrganizationRegistrationScope>
MUST be identical to the set carried by the referenced challenge; a mismatch means the proof was made for different authority than is being claimed.
items · string (enum) · $ref #/$defs/OrganizationRegistrationScope
Closed set of local administrative scopes a registration may delegate. organization_profile_manage covers this deployment's local organization profile and display; organization_realm_endorse permits issuing ak.realm.organization statements on the organization's behalf; organization_service_delegate permits declaring organization-to-service delegations locally. The set is closed because an open scope vocabulary would let a deployment mint authority the organization never consented to. Holding a scope is a permission to act later, not an action: registration by itself creates no Realm, membership, governance-Station authority, capability or service delegation.
enum: "organization_profile_manage" "organization_realm_endorse" "organization_service_delegate"
handle_attestation · object
Optional supporting attestation only. An organization handle or domain claim may improve discovery and display, but MUST NOT substitute for DID control or quorum proof: whoever operates a domain is not thereby the controller of the organization's DID. Named attestation rather than evidence because it carries exactly one material family (common-fields.md R6).
* subject_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* handle · string
* issuer_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* audience · string
* status · string (enum)
The issuer's assertion at signing time. It is a floor, not a guarantee: a receiver MUST still consult the issuer's current revocation state before relying on the handle for display, because a self-asserted active is exactly what a revoked attestation would also carry.
enum: "active" "revoked"
* expires_at · string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
anyOf · anyOf[41] · object · $ref #/$defs/OrganizationRegistrationOutcome
Result of every organization registration command and of the read surface. Identity, DID, generation and version are read from the signed registration_receipt. created is true exactly on a call that opened a new generation.
* registration_receipt · object · $ref #/$defs/OrganizationRegistrationReceipt
Provider-signed record that this deployment accepted an external Organization DID binding. receipt_claims is exactly the object formed by removing registration_receipt_id and proof from the receipt; registration_receipt_id is ak:organization_registration_receipt:<lowercase hex SHA-256(canonical_json(receipt_claims))>. proof.payload_digest hashes the complete receipt after registration_receipt_id is inserted and proof is removed, so neither digest is self-referential. proof is a detached JWS over the ak.organization_registration_receipt_proof.v1 binding object. The receipt proves acceptance of one generation of one local binding and nothing else: it is not a Realm capability, not membership, not a governance-Station designation, and not a service delegation.
* registration_receipt_id · string
ak:organization_registration_receipt: plus lowercase hex SHA-256(canonical_json(receipt with registration_receipt_id and proof both omitted)).
pattern: ^ak:organization_registration_receipt:[0-9a-f]{64}$
* organization_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* organization_did · string · $ref ./common-ids.schema.json#/$defs/did
Canonical bare DID used for registration, DID method resolution and owner-published current resolution. It contains no path, query or fragment and MUST project through the registered method adapter to exactly one did_core_id.
pattern: ^did:[a-z0-9]+:[^\s/?#]+$
* registration_generation · integer
Monotonic generation of the binding for this stable organization did_core_id, starting at 1. A same-core did refresh does not create a different organization identity; terminal registration states remain per generation.
* version_id · string
pattern: ^(?!ak:)
* log_head_digest · string
pattern: ^sha256:[0-9a-f]{64}$
* control_proof_kind · string (enum)
Mirrors OrganizationControlProof.proof_kind so a later auditor can tell which commitment control_key_digest is over without re-fetching the original request.
enum: "resolved_verification_method" "governance_quorum"
* control_key_digest · string
Under resolved_verification_method, the digest of the active control/update public key at version_id. Under governance_quorum, the digest of the canonical governance key set head that satisfied the threshold. It is never a next-key commitment and never private material.
pattern: ^sha256:[0-9a-f]{64}$
* local_admin_subject_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* delegated_scopes · array<$ref #/$defs/OrganizationRegistrationScope>
items · …
recursion truncated at depth 8; see source schema for full shape
* status · string (enum)
Closed lifecycle. active: control evidence is current. stale: the pinned version no longer reflects current control (controller rotation) or the evidence has aged out; low-risk reads may continue but high-risk paths MUST fail closed until a successful refresh. revoked: terminal for this generation, whether withdrawn locally, atomically superseded by a new generation, or forced by deactivation of the external DID. A signed historical receipt can retain status=active as an immutable audit artifact, but it authorizes only while its generation is the registry current generation and that registry state is active.
enum: "active" "stale" "revoked"
* issued_at · string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
* expires_at · string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
* issuer_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* proof · object · $ref ./event-envelope.schema.json#/$defs/proof
Generic detached-JWS proof shape reused by non-Event schemas (snapshot signature, snapshot witness attestations, identity receipts, handle claims, etc.). MUST NOT be used as the shape of Event Envelope `producer_proof` — Event proofs reference $defs/event_proof and bind canonical Event bytes via `event_digest`. Non-Event signed objects MUST define an object-family signing-context constant and include it in the canonical proof binding object with payload_digest; the context constant is not a wire field in this generic shape. drift detection: `payload_digest#event_proof` in forbidden-wire-fields.json is the hard-reject mirror of this rule. New non-Event signed objects MAY $ref this shape; new signed Event-shaped objects MUST instead $ref event_proof.
* kind · …
recursion truncated at depth 8; see source schema for full shape
* verification_method · …
recursion truncated at depth 8; see source schema for full shape
* payload_digest · …
recursion truncated at depth 8; see source schema for full shape
* created_at · …
recursion truncated at depth 8; see source schema for full shape
domain · …
recursion truncated at depth 8; see source schema for full shape
audience · …
recursion truncated at depth 8; see source schema for full shape
proof_purpose · …
recursion truncated at depth 8; see source schema for full shape
* jws · …
recursion truncated at depth 8; see source schema for full shape
* created · boolean
True exactly when this call opened a new generation: the first registration, a re-registration after revoke, or an ensure that changed local_admin_subject or the scope set. False for a byte-identical ensure retry that matches the consumed challenge's canonical_request_digest and stored outcome, and for every read, refresh and revoke. Reusing the challenge with a different digest is an error, not created=false.
anyOf · anyOf[42] · object · $ref #/$defs/OrganizationRegistrationRefreshRequestBody
Re-prove control at a newer resolved version and re-issue the receipt. Scopes are not re-negotiated here; a scope change is a new ensure. Refresh exists because a binding pinned to one version stops proving current control the moment the organization rotates its controller.
* organization_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* organization_did · string · $ref ./common-ids.schema.json#/$defs/did
Canonical bare DID used for registration, DID method resolution and owner-published current resolution. It contains no path, query or fragment and MUST project through the registered method adapter to exactly one did_core_id.
pattern: ^did:[a-z0-9]+:[^\s/?#]+$
* challenge_id · string
pattern: ^ak:organization_registration_challenge:[0-9a-f]{64}$
* version_id · string
pattern: ^(?!ak:)
* log_head_digest · string
pattern: ^sha256:[0-9a-f]{64}$
* control_proof · object · $ref #/$defs/OrganizationControlProof
Method-native proof that the caller controls the external Organization DID at the pinned version. proof_kind is a closed discriminator with exactly two members, both of which describe a MATURE, already-published DID. Creating a new Organization DID is a separate inception / governance ceremony and deliberately has no member here: a receiver must never have to guess whether a proof asserts control of existing state or creation of new state. This object never carries an Arkret-issued challenge signature in place of method-native control evidence.
allOf · allOf[0] · ?
* proof_kind · string (enum)
resolved_verification_method: a single signature by a verification method that is in the organization DID's control relationship at version_id. governance_quorum: a threshold of signatures from the organization's governance key set. Witness attestation is neither of these and MUST NOT be substituted for control evidence (identity-did.md §8.1).
enum: "resolved_verification_method" "governance_quorum"
quorum_threshold · integer
Required when proof_kind=governance_quorum and forbidden otherwise. The number of distinct valid governance signatures the organization's own policy demands. proofs[] MUST contain at least this many entries signed by distinct verification methods; JSON Schema cannot compare the two, so the receiver MUST enforce it and fail closed when short.
* proofs · array<$ref ./event-envelope.schema.json#/$defs/proof>
Detached proofs over canonical_json({context:'ak.organization_registration_control_proof.v1', challenge_id, organization_id, organization_did, local_admin_subject, version_id, log_head_digest, verification_method, created_at}). The verifier independently validates the published organization_did and requires project(organization_did)=organization_id before checking the DID URL verification_method. Binding the challenge, stable core, DID, beneficiary admin and exact version together prevents replay across deployments, resolutions or beneficiaries.
items · …
recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[43] · object · $ref #/$defs/OrganizationRegistrationRevokeRequestBody
Withdraw the local binding. This is a local act with local effect only: it does not modify, deactivate or annotate the external DID's method history, which this deployment does not control.
* organization_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
reason_code · string (enum)
Closed reason set. superseded: replaced by a new binding for the same organization. withdrawn: the deployment or the organization ended the relationship.
enum: "organization_registration_superseded" "organization_registration_withdrawn"
anyOf · anyOf[44] · object · $ref #/$defs/ProjectionMorphList
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* morphs · array<$ref #/$defs/ProjectionMorphRow>
items · object · $ref #/$defs/ProjectionMorphRow
allOf · allOf[0] · …
recursion truncated at depth 8; see source schema for full shape
* morph_id · …
recursion truncated at depth 8; see source schema for full shape
* realm_id · …
recursion truncated at depth 8; see source schema for full shape
* morph_kind · …
recursion truncated at depth 8; see source schema for full shape
title · …
recursion truncated at depth 8; see source schema for full shape
* state · …
recursion truncated at depth 8; see source schema for full shape
state_changed_at · …
recursion truncated at depth 8; see source schema for full shape
stage · …
recursion truncated at depth 8; see source schema for full shape
stage_changed_at · …
recursion truncated at depth 8; see source schema for full shape
created_by · …
recursion truncated at depth 8; see source schema for full shape
created_at · …
recursion truncated at depth 8; see source schema for full shape
updated_at · …
recursion truncated at depth 8; see source schema for full shape
* total · integer
next_cursor · string
pattern: ^ak:cursor:[A-Za-z0-9_-]+$
* has_more · boolean
anyOf · anyOf[45] · object · $ref #/$defs/ProjectionSpaceList
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* spaces · array<$ref #/$defs/ProjectionSpaceRow>
items · object · $ref #/$defs/ProjectionSpaceRow
oneOf · oneOf[0] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · …
recursion truncated at depth 8; see source schema for full shape
* space_id · …
recursion truncated at depth 8; see source schema for full shape
* realm_id · …
recursion truncated at depth 8; see source schema for full shape
* kind · …
recursion truncated at depth 8; see source schema for full shape
title · …
recursion truncated at depth 8; see source schema for full shape
encrypted_metadata · …
recursion truncated at depth 8; see source schema for full shape
parent_space_id · …
recursion truncated at depth 8; see source schema for full shape
rank · …
recursion truncated at depth 8; see source schema for full shape
* state · …
recursion truncated at depth 8; see source schema for full shape
state_changed_at · …
recursion truncated at depth 8; see source schema for full shape
created_by · …
recursion truncated at depth 8; see source schema for full shape
created_at · …
recursion truncated at depth 8; see source schema for full shape
updated_at · …
recursion truncated at depth 8; see source schema for full shape
* total · integer
next_cursor · string
pattern: ^ak:cursor:[A-Za-z0-9_-]+$
* has_more · boolean
anyOf · anyOf[46] · object · $ref #/$defs/ProjectionStrandList
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* strands · array<$ref #/$defs/ProjectionStrandRow>
items · object · $ref #/$defs/ProjectionStrandRow
allOf · allOf[0] · …
recursion truncated at depth 8; see source schema for full shape
* strand_id · …
recursion truncated at depth 8; see source schema for full shape
* realm_id · …
recursion truncated at depth 8; see source schema for full shape
* state · …
recursion truncated at depth 8; see source schema for full shape
state_changed_at · …
recursion truncated at depth 8; see source schema for full shape
stage · …
recursion truncated at depth 8; see source schema for full shape
stage_changed_at · …
recursion truncated at depth 8; see source schema for full shape
title · …
recursion truncated at depth 8; see source schema for full shape
summary · …
recursion truncated at depth 8; see source schema for full shape
topic · …
recursion truncated at depth 8; see source schema for full shape
board_space_id · …
recursion truncated at depth 8; see source schema for full shape
list_space_id · …
recursion truncated at depth 8; see source schema for full shape
rank · …
recursion truncated at depth 8; see source schema for full shape
assigned_actor_ids · …
recursion truncated at depth 8; see source schema for full shape
assigned_to_relations · …
recursion truncated at depth 8; see source schema for full shape
created_by · …
recursion truncated at depth 8; see source schema for full shape
created_at · …
recursion truncated at depth 8; see source schema for full shape
updated_by · …
recursion truncated at depth 8; see source schema for full shape
updated_at · …
recursion truncated at depth 8; see source schema for full shape
* is_default · …
recursion truncated at depth 8; see source schema for full shape
* total · integer
next_cursor · string
pattern: ^ak:cursor:[A-Za-z0-9_-]+$
* has_more · boolean
anyOf · anyOf[47] · object · $ref #/$defs/StrandWatchCurrentRequestBody
Exact self watch selector. It cannot enumerate watchers or supply an expected CAS value.
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* strand_id · string · $ref ./event-payload.schema.json#/$defs/strand_id
pattern: ^ak:strand:[A-Za-z0-9_-]{44}$
* watcher_actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind · …
recursion truncated at depth 8; see source schema for full shape
* account_id · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* kind · …
recursion truncated at depth 8; see source schema for full shape
* service_id · …
recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[48] · oneOf[2] · $ref #/$defs/StrandWatchCurrentOutcome
A verified never-written fact is distinct from a written result whose value was cleared to null.
oneOf · oneOf[0] · object · $ref #/$defs/StrandWatchCurrentNeverWritten
* status · const "never_written"
enum: "never_written"
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* governance_generation · integer
* stream_head · object · $ref ./realm-commit.schema.json#/$defs/stream_head
* stream_ref · …
recursion truncated at depth 8; see source schema for full shape
* stream_position · …
recursion truncated at depth 8; see source schema for full shape
* commit_id · …
recursion truncated at depth 8; see source schema for full shape
* selector · object · $ref ./typed-current-result.schema.json#/$defs/strand_watch_result/properties/selector
* kind · …
recursion truncated at depth 8; see source schema for full shape
* strand_id · …
recursion truncated at depth 8; see source schema for full shape
* watcher_actor_id · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object · $ref #/$defs/StrandWatchCurrentPresent
* status · const "current"
enum: "current"
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* governance_generation · integer
* stream_head · object · $ref ./realm-commit.schema.json#/$defs/stream_head
* stream_ref · …
recursion truncated at depth 8; see source schema for full shape
* stream_position · …
recursion truncated at depth 8; see source schema for full shape
* commit_id · …
recursion truncated at depth 8; see source schema for full shape
* result · object · $ref ./typed-current-result.schema.json#/$defs/strand_watch_result
* selector · …
recursion truncated at depth 8; see source schema for full shape
* source_stream_ref · …
recursion truncated at depth 8; see source schema for full shape
* revision · …
recursion truncated at depth 8; see source schema for full shape
* value · …
recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[49] · object · $ref #/$defs/ServiceRegistrationEnsureRequestBody
* service_kind · string (enum) · $ref #/$defs/ServiceRegistrationKey/properties/service_kind
enum: "station" "identity_registry"
* public_base_url · string (uri) · format=uri · $ref #/$defs/ServiceRegistrationKey/properties/public_base_url
Canonical service base URL: lower-case scheme and host, no query or fragment, normalized path, and exactly one trailing slash. Production deployments MUST use https; explicit development deployments MAY use http.
pattern: ^https?://[^?#]+/$
* did · string · $ref ./common-ids.schema.json#/$defs/did
Canonical bare DID used for registration, DID method resolution and owner-published current resolution. It contains no path, query or fragment and MUST project through the registered method adapter to exactly one did_core_id.
pattern: ^did:[a-z0-9]+:[^\s/?#]+$
* inception_operation · object · $ref #/$defs/ServiceWebvhInceptionOperation
* versionId · string
pattern: ^1-[1-9A-HJ-NP-Za-km-z]+$
* versionTime · string (date-time) · format=date-time
* parameters · object · $ref #/$defs/ServiceWebvhInceptionParameters
* scid · …
recursion truncated at depth 8; see source schema for full shape
* method · …
recursion truncated at depth 8; see source schema for full shape
* updateKeys · …
recursion truncated at depth 8; see source schema for full shape
* nextKeyHashes · …
recursion truncated at depth 8; see source schema for full shape
* state · object · $ref #/$defs/ServiceDidDocument
* @context · …
recursion truncated at depth 8; see source schema for full shape
* id · …
recursion truncated at depth 8; see source schema for full shape
alsoKnownAs · …
recursion truncated at depth 8; see source schema for full shape
* verificationMethod · …
recursion truncated at depth 8; see source schema for full shape
* authentication · …
recursion truncated at depth 8; see source schema for full shape
* assertionMethod · …
recursion truncated at depth 8; see source schema for full shape
* service · …
recursion truncated at depth 8; see source schema for full shape
* proof · array<$ref #/$defs/ServiceWebvhDataIntegrityProof>
items · …
recursion truncated at depth 8; see source schema for full shape
* idempotency_key · string · $ref ./principal-operations.schema.json#/$defs/opaque_id
Bounded opaque caller-chosen correlation string used only to relate audit records for one ensure attempt. It is deliberately outside the ak: typed-ID namespace and MUST NOT be parsed by the typed-ID parser or treated as an object identity. Registration identity is the canonical (service_kind, public_base_url) key that Provider persistence enforces with UNIQUE(service_kind, public_base_url), and the single idempotency authority for this operation is the operation registry's idempotency_mechanism=object_id; this field never establishes a second one.
previous_receipt · oneOf[2]
oneOf · oneOf[0] · object · $ref #/$defs/ServiceRegistrationReceipt
Provider-signed stable service-registration receipt. registration_receipt_id is ak:service_registration_receipt:<lowercase hex SHA-256(canonical_json(receipt claims))>. service_id is the projected did_core_id and did is the verified DID. proof is a detached JWS over the ak.service_registration_receipt_proof.v1 binding object; consumers verify the provider through its own resolution evidence.
* registration_receipt_id · …
recursion truncated at depth 8; see source schema for full shape
* registration_key · …
recursion truncated at depth 8; see source schema for full shape
* service_id · …
recursion truncated at depth 8; see source schema for full shape
* did · …
recursion truncated at depth 8; see source schema for full shape
* version_id · …
recursion truncated at depth 8; see source schema for full shape
* log_head_digest · …
recursion truncated at depth 8; see source schema for full shape
* control_key_digest · …
recursion truncated at depth 8; see source schema for full shape
* issued_at · …
recursion truncated at depth 8; see source schema for full shape
* provider_id · …
recursion truncated at depth 8; see source schema for full shape
* proof · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · null
anyOf · anyOf[50] · object · $ref #/$defs/ServiceRegistrationOutcome
* did_document · object · $ref #/$defs/ServiceDidDocument
* @context · array<string (uri)>
items · …
recursion truncated at depth 8; see source schema for full shape
* id · string · $ref ./common-ids.schema.json#/$defs/webvh_did
Canonical bare did:webvh identifier used at method-native registration, document and evidence boundaries. Role admission is enforced separately.
pattern: ^did:webvh:[^\s:/?#]+:[^\s/?#]+$
alsoKnownAs · array<string (uri)>
items · …
recursion truncated at depth 8; see source schema for full shape
* verificationMethod · array<$ref #/$defs/ServiceDidVerificationMethod>
items · …
recursion truncated at depth 8; see source schema for full shape
* authentication · array<string>
items · …
recursion truncated at depth 8; see source schema for full shape
* assertionMethod · array<string>
items · …
recursion truncated at depth 8; see source schema for full shape
* service · array<$ref #/$defs/ServiceDidEndpoint>
items · …
recursion truncated at depth 8; see source schema for full shape
* registration_receipt · object · $ref #/$defs/ServiceRegistrationReceipt
Provider-signed stable service-registration receipt. registration_receipt_id is ak:service_registration_receipt:<lowercase hex SHA-256(canonical_json(receipt claims))>. service_id is the projected did_core_id and did is the verified DID. proof is a detached JWS over the ak.service_registration_receipt_proof.v1 binding object; consumers verify the provider through its own resolution evidence.
* registration_receipt_id · string
pattern: ^ak:service_registration_receipt:[0-9a-f]{64}$
* registration_key · object · $ref #/$defs/ServiceRegistrationKey
* service_kind · …
recursion truncated at depth 8; see source schema for full shape
* public_base_url · …
recursion truncated at depth 8; see source schema for full shape
* service_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* did · string · $ref ./common-ids.schema.json#/$defs/did
Canonical bare DID used for registration, DID method resolution and owner-published current resolution. It contains no path, query or fragment and MUST project through the registered method adapter to exactly one did_core_id.
pattern: ^did:[a-z0-9]+:[^\s/?#]+$
* version_id · string
pattern: ^(?!ak:)
* log_head_digest · string
pattern: ^sha256:[0-9a-f]{64}$
* control_key_digest · string
Digest of the active control/update public key at version_id; this is not the next-key commitment or private recovery material.
pattern: ^sha256:[0-9a-f]{64}$
* issued_at · string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
* provider_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* proof · object · $ref ./event-envelope.schema.json#/$defs/proof
Generic detached-JWS proof shape reused by non-Event schemas (snapshot signature, snapshot witness attestations, identity receipts, handle claims, etc.). MUST NOT be used as the shape of Event Envelope `producer_proof` — Event proofs reference $defs/event_proof and bind canonical Event bytes via `event_digest`. Non-Event signed objects MUST define an object-family signing-context constant and include it in the canonical proof binding object with payload_digest; the context constant is not a wire field in this generic shape. drift detection: `payload_digest#event_proof` in forbidden-wire-fields.json is the hard-reject mirror of this rule. New non-Event signed objects MAY $ref this shape; new signed Event-shaped objects MUST instead $ref event_proof.
* kind · …
recursion truncated at depth 8; see source schema for full shape
* verification_method · …
recursion truncated at depth 8; see source schema for full shape
* payload_digest · …
recursion truncated at depth 8; see source schema for full shape
* created_at · …
recursion truncated at depth 8; see source schema for full shape
domain · …
recursion truncated at depth 8; see source schema for full shape
audience · …
recursion truncated at depth 8; see source schema for full shape
proof_purpose · …
recursion truncated at depth 8; see source schema for full shape
* jws · …
recursion truncated at depth 8; see source schema for full shape
* created · boolean
anyOf · anyOf[51] · object · $ref #/$defs/SessionGrantIntrospectOutcome
allOf · allOf[0] · ?
* active · boolean
Whether the grant is currently valid for the requested audience. READ-ONLY: introspection never consumes the grant.
* status · string (enum)
enum: "active" "revoked" "superseded" "expired" "locked" "suspended" "audience_mismatch" "proof_required" "invalid_proof" "not_found"
* proof_required · boolean
Whether an additional S2S holder proof is required to confirm the grant active for this introspection request. Default Station grant+DPoP validation uses the request DPoP instead of this field.
* one_time_use_consumed · boolean
Always false: introspection is read-only and never consumes single-use state (rotation is the refresh endpoint's job).
grant · object · $ref #/$defs/SessionGrantIntrospectGrant
Non-secret grant metadata returned to the validating Station. Never includes the grant JWT, refresh token, or session private key.
allOf · allOf[0] · ?
allOf · allOf[1] · ?
allOf · allOf[2] · ?
allOf · allOf[3] · ?
* id · string · $ref ./common-ids.schema.json#/$defs/session_grant_id
pattern: ^ak:session_grant:[A-Za-z0-9_-]{44}$
* issuer_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id · …
recursion truncated at depth 8; see source schema for full shape
* station_id · …
recursion truncated at depth 8; see source schema for full shape
device_id · string · $ref ./common-ids.schema.json#/$defs/device_id
pattern: ^ak:device:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$
* audience_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* scopes · array<string>
items · …
recursion truncated at depth 8; see source schema for full shape
* expires_at · string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
revoked_at · string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
* revocation_ref · string
* session_public_key · string
Session signing key (JWK) for RFC 9421 PoP verification on /_arkret/self/* (api-conventions §3.2). Server-to-server only.
* cnf_jkt · string
RFC 7638 JWK SHA-256 thumbprint of the holder (DPoP) key the grant is bound to (cnf.jkt); the Station uses it to verify the per-request DPoP proof on /_arkret/self/* (api-conventions §3.3). Server-to-server only.
* credential_class · string (enum) · $ref #/$defs/SessionGrantCredentialClass
Closed credential class. recovery_session is a <=15 minute, non-refreshable, DPoP-bound candidate-device grant restricted to the exact recovery operation set; recovery completion issues a distinct standard grant.
enum: "standard" "recovery_session"
* holder_binding · oneOf[3] · $ref ./principal-operations.schema.json#/$defs/session_grant_holder_binding
Required closed accepted human-device, recovery candidate-device, or Agent-runtime holder binding.
oneOf · oneOf[0] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[2] · …
recursion truncated at depth 8; see source schema for full shape
device_binding · object · $ref #/$defs/SessionGrantDeviceBinding
Authorization state committed into a standard device grant. An Account Authority MUST populate it verbatim from the Station TCB current-device decision, which is the only source of the origin-derived authorization Event and generation; it MUST NOT be taken from client input, a local cache or a private lookup. Stations compare it with the current active device generation on admission.
* device_id · …
recursion truncated at depth 8; see source schema for full shape
* authorization_event_id · …
recursion truncated at depth 8; see source schema for full shape
* model_generation_ref · …
recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[52] · object · $ref #/$defs/SessionGrantIntrospectRequestBody
Server-to-server session-grant introspection request. Exactly one of id / grant_jwt identifies the grant.
oneOf · oneOf[0] · ?
oneOf · oneOf[1] · ?
id · string · $ref ./common-ids.schema.json#/$defs/session_grant_id
Grant id. Mutually exclusive with grant_jwt.
pattern: ^ak:session_grant:[A-Za-z0-9_-]{44}$
grant_jwt · string
The signed grant JWT to introspect. Mutually exclusive with id.
audience_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
proof · object
Optional S2S holder confirmation signed by the session key bound into the grant. Stations validating /_arkret/self/* grant+DPoP requests do not require a client-carried introspection proof; they verify the request DPoP locally against the returned cnf_jkt.
* challenge · string
* proof_jwt · string
JWS over ak.session_grant.introspection_proof.v1 claims (session_grant_id, grant_jwt_digest, audience, challenge, issued_at, expires_at).
anyOf · anyOf[53] · object · $ref #/$defs/SessionGrantOutcome
* account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id · $ref #/$defs/did_core_id · $ref #/$defs/did_core_id
* station_id · $ref #/$defs/did_core_id · $ref #/$defs/did_core_id
device_id · string
pattern: ^ak:device:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$
* session_grant · string
Short-lived bearer/session grant bound to the requested principal, device and audience.
* expires_at · string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
* session_grant_id · string · $ref ./common-ids.schema.json#/$defs/session_grant_id
Stable id of the issued or rotated session grant. Returned for every grant so the client can reference, refresh, introspect or revoke this exact grant without re-parsing the opaque session_grant.
pattern: ^ak:session_grant:[A-Za-z0-9_-]{44}$
* session_public_key · string (canonical-public-jwk-jcs) · format=canonical-public-jwk-jcs
JWK of the holder/session key the grant is bound to (the device holder key). The client needs this to perform RFC 9421 PoP and to derive the DPoP cnf.jkt for /_arkret/self/* requests (api-conventions.md §3.2 / §3.3); returning it avoids a mandatory introspect round-trip before the first self-path request.
* audience_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* granted_scope · array<string>
items · string
previous_session_grant_id · string · $ref ./common-ids.schema.json#/$defs/session_grant_id
Present only on refresh. The predecessor grant atomically superseded by this successor.
pattern: ^ak:session_grant:[A-Za-z0-9_-]{44}$
anyOf · anyOf[54] · oneOf[2] · $ref #/$defs/SessionGrantRefreshRequestBody
Closed human-versus-Agent SessionGrant rotation union. Neither branch accepts a client-generated challenge or a generic proof_kind enum.
oneOf · oneOf[0] · object · $ref #/$defs/HumanSessionGrantRefreshRequest
* grant_jwt · string
Near-expiry human DPoP-bound SessionGrant presented as Authorization: DPoP plus a matching DPoP proof.
audience_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* device_id · string · $ref ./common-ids.schema.json#/$defs/device_id
pattern: ^ak:device:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$
* accepted_device_possession_proof · object · $ref #/$defs/AcceptedDevicePossessionProof
Accepted-device Ed25519 possession proof shared by human SessionGrant issue and refresh. The signature covers utf8('ak.session_grant_accepted_device_possession_proof.v1\n') followed by RFC 8785 JCS of this complete object with signature omitted. It is not a server challenge: freshness comes from the <=300 second signed window, the one-time account handoff or predecessor grant, the issuer request identity, and issuer-ledger exact replay. The origin Station MUST verify this proof with the durable current accepted-device key in the same linearization that evaluates current authorization.
allOf · allOf[0] · …
recursion truncated at depth 8; see source schema for full shape
* context · …
recursion truncated at depth 8; see source schema for full shape
* purpose · …
recursion truncated at depth 8; see source schema for full shape
request_id · …
recursion truncated at depth 8; see source schema for full shape
account_subject · …
recursion truncated at depth 8; see source schema for full shape
account_handoff_grant_digest · …
recursion truncated at depth 8; see source schema for full shape
predecessor_session_grant_id · …
recursion truncated at depth 8; see source schema for full shape
* account_id · …
recursion truncated at depth 8; see source schema for full shape
* device_id · …
recursion truncated at depth 8; see source schema for full shape
* audience_id · …
recursion truncated at depth 8; see source schema for full shape
* holder_jkt · …
recursion truncated at depth 8; see source schema for full shape
* session_intent_digest · …
recursion truncated at depth 8; see source schema for full shape
* issued_at · …
recursion truncated at depth 8; see source schema for full shape
* expires_at · …
recursion truncated at depth 8; see source schema for full shape
* verification_method · …
recursion truncated at depth 8; see source schema for full shape
* signature · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object · $ref #/$defs/AgentSessionGrantRefreshRequest
Agent rotation binds the predecessor grant's agent_id, accepted agent_key_authorization_ref and proof.verification_method. Agent MLS endpoints have no device_id; a refresh carrying one is invalid.
* grant_jwt · string
Near-expiry Agent DPoP-bound SessionGrant presented as Authorization: DPoP plus a matching DPoP proof.
audience_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* principal_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* agent_key_authorization_ref · string · $ref ./account-operations.schema.json#/$defs/event_id
pattern: ^ak:event:[A-Za-z0-9_-]{44}$
* agent_session_refresh_proof · object · $ref #/$defs/AgentSessionRefreshProof
Current Agent runtime-key proof for SessionGrant rotation. It is a distinct branch from accepted human-device PoP and carries no client-generated challenge or polymorphic proof_kind.
* context · …
recursion truncated at depth 8; see source schema for full shape
* request_canonical_digest · …
recursion truncated at depth 8; see source schema for full shape
* audience_id · …
recursion truncated at depth 8; see source schema for full shape
* issued_at · …
recursion truncated at depth 8; see source schema for full shape
* expires_at · …
recursion truncated at depth 8; see source schema for full shape
* verification_method · …
recursion truncated at depth 8; see source schema for full shape
* signature · …
recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[55] · object · $ref #/$defs/SessionGrantReplayExpiredProblem
Closed RFC 9457 Problem Details extension members for session_grant_replay_expired. The named issuer-ledger record remains authoritative and no replacement grant is created under the same request identity.
* session_grant_id · string · $ref ./common-ids.schema.json#/$defs/session_grant_id
pattern: ^ak:session_grant:[A-Za-z0-9_-]{44}$
* state · const "expired"
Retained on purpose: this is an RFC 9457 Problem Details extension member on the failure path and names the issuer-ledger state that caused the rejection, so the problem document stays self-describing next to SessionGrantReplayTerminalProblem. It is not a success-only outcome constant.
enum: "expired"
anyOf · anyOf[56] · object · $ref #/$defs/SessionGrantReplayTerminalProblem
Closed RFC 9457 Problem Details extension members for session_grant_replay_terminal. The state is an exact durable issuer-ledger terminal state and no replacement grant is created under the same request identity.
* session_grant_id · string · $ref ./common-ids.schema.json#/$defs/session_grant_id
pattern: ^ak:session_grant:[A-Za-z0-9_-]{44}$
* state · string (enum)
enum: "revoked" "superseded"
anyOf · anyOf[57] · oneOf[3] · $ref #/$defs/SessionGrantRequestBody
Closed returning-human, Agent runtime or fresh-device recovery issuance union. OIDC authorization codes are consumed only by account_handoff_request_body and never by this operation.
oneOf · oneOf[0] · object · $ref #/$defs/HumanSessionGrantRequest
Returning-human issuance from an already bound account. Authorization is the DPoP-bound account_handoff_grant plus matching per-request DPoP; the body deliberately carries neither a second holder signature nor requested_scope.
* request_id · string
pattern: ^ak:request:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$
* principal_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* device_id · string · $ref ./common-ids.schema.json#/$defs/device_id
pattern: ^ak:device:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$
* audience_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* accepted_device_possession_proof · object · $ref #/$defs/AcceptedDevicePossessionProof
Accepted-device Ed25519 possession proof shared by human SessionGrant issue and refresh. The signature covers utf8('ak.session_grant_accepted_device_possession_proof.v1\n') followed by RFC 8785 JCS of this complete object with signature omitted. It is not a server challenge: freshness comes from the <=300 second signed window, the one-time account handoff or predecessor grant, the issuer request identity, and issuer-ledger exact replay. The origin Station MUST verify this proof with the durable current accepted-device key in the same linearization that evaluates current authorization.
allOf · allOf[0] · …
recursion truncated at depth 8; see source schema for full shape
* context · …
recursion truncated at depth 8; see source schema for full shape
* purpose · …
recursion truncated at depth 8; see source schema for full shape
request_id · …
recursion truncated at depth 8; see source schema for full shape
account_subject · …
recursion truncated at depth 8; see source schema for full shape
account_handoff_grant_digest · …
recursion truncated at depth 8; see source schema for full shape
predecessor_session_grant_id · …
recursion truncated at depth 8; see source schema for full shape
* account_id · …
recursion truncated at depth 8; see source schema for full shape
* device_id · …
recursion truncated at depth 8; see source schema for full shape
* audience_id · …
recursion truncated at depth 8; see source schema for full shape
* holder_jkt · …
recursion truncated at depth 8; see source schema for full shape
* session_intent_digest · …
recursion truncated at depth 8; see source schema for full shape
* issued_at · …
recursion truncated at depth 8; see source schema for full shape
* expires_at · …
recursion truncated at depth 8; see source schema for full shape
* verification_method · …
recursion truncated at depth 8; see source schema for full shape
* signature · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object · $ref #/$defs/AgentSessionGrantRequest
Agent runtime session issuance is bound to principal_id (agent_id), proof.verification_method and the current accepted agent_key_authorization_ref. This closed branch MUST NOT carry a device_id or derive one from the Agent key.
* principal_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* requested_scope · array<string>
items · …
recursion truncated at depth 8; see source schema for full shape
* agent_key_authorization_ref · string
`ak.profile.agent_auth.v1` overlay. Event ref of the accepted `ak.agent.key.authorize` that authorized the runtime key. REQUIRED when `proof.proof_kind="agent_key_proof"`; MUST be omitted for human session grants.
pattern: ^ak:event:[A-Za-z0-9_-]{44}$
* agent_scope_request · object
`ak.profile.agent_auth.v1` overlay. Narrowing hints for the issued session scope. Service-surface requested_scope values are intersected with the immutable provision requested_scope, accepted agent_key_scope and endpoint/resource policy; content actions are additionally intersected with independent effective Realm capability grants, participation, membership, history visibility and E2EE policy. Provision mandatory constraints remain in force at every layer. REQUIRED when `proof.proof_kind="agent_key_proof"`; MUST be omitted for human session grants. `track_names` is a request-side narrowing field only — the materialized session grant MUST express track scope via the canonical `allowed_tracks` constraint, not via a new `track_names` grant.
realm_ids · …
recursion truncated at depth 8; see source schema for full shape
strand_ids · …
recursion truncated at depth 8; see source schema for full shape
track_names · …
recursion truncated at depth 8; see source schema for full shape
requested_scope_disclosure · object · $ref ./agent-requested-scope-disclosure.schema.json
Controller-signed, verifier-bound private disclosure of an Agent's immutable requested_scope. This object is authorization evidence, not a grant. It MUST travel only over an authenticated confidential presentation/operation channel and MUST NOT be written to a public DID Document, durable Realm Event, public registry, pairing code, or notification. The verifier consumes request_id/challenge once, validates the short presentation window, verifies a current controller proof, recomputes the requested-scope commitment against the accepted-at Agent DID commitment, and then applies the Agent ceiling subset rules. After successful one-time admission, an implementation MAY retain the object only as encrypted verifier-private evidence keyed by the recomputed digest, verifier_id and audience.
* schema · …
recursion truncated at depth 8; see source schema for full shape
* request_id · …
recursion truncated at depth 8; see source schema for full shape
* agent_id · …
recursion truncated at depth 8; see source schema for full shape
* controller_principal_id · …
recursion truncated at depth 8; see source schema for full shape
* requested_scope · …
recursion truncated at depth 8; see source schema for full shape
* verifier_id · …
recursion truncated at depth 8; see source schema for full shape
* audience · …
recursion truncated at depth 8; see source schema for full shape
* challenge · …
recursion truncated at depth 8; see source schema for full shape
* issued_at · …
recursion truncated at depth 8; see source schema for full shape
* expires_at · …
recursion truncated at depth 8; see source schema for full shape
* proofs · …
recursion truncated at depth 8; see source schema for full shape
* dpop_binding_proof · object · $ref #/$defs/SessionGrantDpopBindingProof
`ak.profile.agent_auth.v1` overlay. DPoP proof JWT for the holder key that the issued session grant will bind to. REQUIRED when `proof.proof_kind="agent_key_proof"`; the Account Authority verifies the proof and materializes the resulting JWK thumbprint into the issued grant's `cnf.jkt` / session_public_key binding.
* proof_jwt · …
recursion truncated at depth 8; see source schema for full shape
* proof · object
Closed initial Agent proof. Require 0 < expires_at-issued_at <= 300 seconds, issued_at <= now+30 seconds, and now < expires_at for first validation. No additional nonce. Exact completed issuer-ledger replay reuses durable one-shot verification, with fresh matching-holder HTTP DPoP.
* proof_kind · …
recursion truncated at depth 8; see source schema for full shape
* challenge · …
recursion truncated at depth 8; see source schema for full shape
* request_canonical_digest · …
recursion truncated at depth 8; see source schema for full shape
* audience_id · …
recursion truncated at depth 8; see source schema for full shape
* issued_at · …
recursion truncated at depth 8; see source schema for full shape
* expires_at · …
recursion truncated at depth 8; see source schema for full shape
* verification_method · …
recursion truncated at depth 8; see source schema for full shape
* signature · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[2] · object · $ref #/$defs/RecoverySessionGrantRequest
Fresh-device existing-principal recovery issuance. Authorization is the Bound AccountHandoff plus matching per-request DPoP. The Account Authority binds this request to its account/principal mapping and does not consume the handoff on success.
* credential_class · const "recovery_session"
enum: "recovery_session"
* request_id · string
pattern: ^ak:request:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$
* principal_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* device_id · string · $ref ./common-ids.schema.json#/$defs/device_id
pattern: ^ak:device:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$
* audience_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
anyOf · anyOf[58] · object · $ref #/$defs/SignalSubmitOutcome
Result of transient Signal admission. accepted=true means the service placed the encrypted envelope on the short-lived rail; it creates no Event, RealmCommit, authority-stream position or durable delivery receipt.
* accepted · boolean
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* envelope_digest · string
Digest of the admitted complete encrypted envelope, used only for short-lived replay suppression and local correlation.
pattern: ^(sha256|blake3):[0-9a-f]{64}$
dispatched_recipient_count · integer
Optional implementation hint for fanout recipients queued locally.
server_received_at · string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
anyOf · anyOf[59] · object · $ref #/$defs/SignedSessionGrantClaims
Canonical signed claims carried by an ak.session.grant JWT. Except for the fixed kind and derived jti, the closed issuance preimage fields are copied from these claims. credential_class and holder_binding are signed and jointly determine the authorization profile; recovery_session is never refreshable or upgradable and recovery completion issues a distinct standard credential. Verifiers MUST RFC 8785-canonicalize the complete claim-derived preimage, recompute SHA-256, prepend the active sha256 suite wire code, derive ak:session_grant:<44-char-token>, and require byte equality with jti. Changing either binding therefore changes the ID.
allOf · allOf[0] · ?
allOf · allOf[1] · ?
* kind · const "ak.session.grant"
enum: "ak.session.grant"
* jti · string · $ref ./common-ids.schema.json#/$defs/session_grant_id
pattern: ^ak:session_grant:[A-Za-z0-9_-]{44}$
* issuer_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* issuance_nonce · string
Canonical unpadded Base64URL encoding of the issuer-generated 256-bit issuance nonce. Exact replay reuses the same nonce, issuance preimage, grant ID and JWT.
pattern: ^[A-Za-z0-9_-]{43}$
* account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id · $ref #/$defs/did_core_id · $ref #/$defs/did_core_id
* station_id · $ref #/$defs/did_core_id · $ref #/$defs/did_core_id
* session_public_key · string (canonical-public-jwk-jcs) · format=canonical-public-jwk-jcs
A supported public JWK serialized as its exact RFC 8785 JCS UTF-8 string. Producers MUST parse and canonicalize input before signing; consumers MUST reject strings whose parsed JWK re-serialization is not byte-identical. Private JWK members are forbidden.
* audience_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* scopes · array<string>
items · string
* not_before · string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
* expires_at · string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
* session_id · string
pattern: ^(?!ak:)
* credential_class · string (enum) · $ref #/$defs/SessionGrantCredentialClass
Closed credential class. recovery_session is a <=15 minute, non-refreshable, DPoP-bound candidate-device grant restricted to the exact recovery operation set; recovery completion issues a distinct standard grant.
enum: "standard" "recovery_session"
device_binding · object · $ref #/$defs/SessionGrantDeviceBinding
Authorization state committed into a standard device grant. An Account Authority MUST populate it verbatim from the Station TCB current-device decision, which is the only source of the origin-derived authorization Event and generation; it MUST NOT be taken from client input, a local cache or a private lookup. Stations compare it with the current active device generation on admission.
* device_id · string · $ref ./common-ids.schema.json#/$defs/device_id
pattern: ^ak:device:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$
* authorization_event_id · string
pattern: ^ak:event:[A-Za-z0-9_-]{44}$
* model_generation_ref · integer · $ref ./recovery-session.schema.json#/$defs/pcr_generation_ref
PCR-local monotonic generation. It MUST NOT equal or be derived from a DID versionId.
* holder_binding · oneOf[3] · $ref ./principal-operations.schema.json#/$defs/session_grant_holder_binding
oneOf · oneOf[0] · object
* kind · …
recursion truncated at depth 8; see source schema for full shape
* device_binding · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* kind · …
recursion truncated at depth 8; see source schema for full shape
* agent_id · …
recursion truncated at depth 8; see source schema for full shape
* agent_key_authorization_ref · …
recursion truncated at depth 8; see source schema for full shape
* verification_method · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[2] · object
* kind · …
recursion truncated at depth 8; see source schema for full shape
* device_id · …
recursion truncated at depth 8; see source schema for full shape
proof_kind · string (enum)
enum: "account_handoff" "agent_key_proof"
scope_details · object
anyOf · anyOf[60] · oneOf[2] · $ref #/$defs/CommittedEventView
Caller-scoped, non-durable read representation pairing one RealmCommit with either the exact producer-signed Event or a minimal withheld marker. It has no independent identity, signature or persistence semantics and is never reducer input.
oneOf · oneOf[0] · object
* commit · object · $ref ./realm-commit.schema.json
The only shared Realm acceptance, ordering, finality and replication record. Every visibility scope has an authority-signed predecessor chain.
allOf · allOf[0] · …
recursion truncated at depth 8; see source schema for full shape
* commit_id · …
recursion truncated at depth 8; see source schema for full shape
* realm_id · …
recursion truncated at depth 8; see source schema for full shape
* stream_ref · …
recursion truncated at depth 8; see source schema for full shape
* stream_position · …
recursion truncated at depth 8; see source schema for full shape
* previous_commit_ref · …
recursion truncated at depth 8; see source schema for full shape
* event_ref · …
recursion truncated at depth 8; see source schema for full shape
* governance_generation · …
recursion truncated at depth 8; see source schema for full shape
* authority_ref · …
recursion truncated at depth 8; see source schema for full shape
* committed_at · …
recursion truncated at depth 8; see source schema for full shape
producer_signer_fact_digest · …
recursion truncated at depth 8; see source schema for full shape
* signature · …
recursion truncated at depth 8; see source schema for full shape
* event · allOf[2] · $ref ./event-envelope.schema.json#/$defs/shared_event_envelope
allOf · allOf[0] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* commit · object · $ref ./realm-commit.schema.json
The only shared Realm acceptance, ordering, finality and replication record. Every visibility scope has an authority-signed predecessor chain.
allOf · allOf[0] · …
recursion truncated at depth 8; see source schema for full shape
* commit_id · …
recursion truncated at depth 8; see source schema for full shape
* realm_id · …
recursion truncated at depth 8; see source schema for full shape
* stream_ref · …
recursion truncated at depth 8; see source schema for full shape
* stream_position · …
recursion truncated at depth 8; see source schema for full shape
* previous_commit_ref · …
recursion truncated at depth 8; see source schema for full shape
* event_ref · …
recursion truncated at depth 8; see source schema for full shape
* governance_generation · …
recursion truncated at depth 8; see source schema for full shape
* authority_ref · …
recursion truncated at depth 8; see source schema for full shape
* committed_at · …
recursion truncated at depth 8; see source schema for full shape
producer_signer_fact_digest · …
recursion truncated at depth 8; see source schema for full shape
* signature · …
recursion truncated at depth 8; see source schema for full shape
* event_disclosure · object · $ref #/$defs/EventDisclosure
Caller-scoped marker stating that canonical Event bytes are withheld. It carries no Event identity, reason, digest, preview or reducer input.
* status · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] · object
context · const "ak.realm_commit_signature.v1"
enum: "ak.realm_commit_signature.v1"
* event · allOf[2] · $ref ./event-envelope.schema.json#/$defs/shared_event_envelope
allOf · allOf[0] · anyOf[61] · $ref #
Canonical DTOs reachable from current authority-commit operations. Every definition is part of the current operation closure.
anyOf · anyOf[0] · object · $ref #/$defs/AcceptedDevicePossessionProof
Accepted-device Ed25519 possession proof shared by human SessionGrant issue and refresh. The signature covers utf8('ak.session_grant_accepted_device_possession_proof.v1\n') followed by RFC 8785 JCS of this complete object with signature omitted. It is not a server challenge: freshness comes from the <=300 second signed window, the one-time account handoff or predecessor grant, the issuer request identity, and issuer-ledger exact replay. The origin Station MUST verify this proof with the durable current accepted-device key in the same linearization that evaluates current authorization.
allOf · allOf[0] · ?
* context · const "ak.session_grant_accepted_device_possession_proof.v1"
enum: "ak.session_grant_accepted_device_possession_proof.v1"
* purpose · string (enum)
enum: "session_grant_issue" "session_grant_refresh"
request_id · string
pattern: ^ak:request:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$
account_subject · string
pattern: ^sha256:[0-9a-f]{64}$
account_handoff_grant_digest · string
SHA-256 digest of the exact opaque DPoP-bound account_handoff_grant presented in Authorization; the credential itself MUST NOT enter the proof or logs.
pattern: ^sha256:[0-9a-f]{64}$
predecessor_session_grant_id · string · $ref ./common-ids.schema.json#/$defs/session_grant_id
pattern: ^ak:session_grant:[A-Za-z0-9_-]{44}$
* account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id · $ref #/$defs/did_core_id · $ref #/$defs/did_core_id
* station_id · $ref #/$defs/did_core_id · $ref #/$defs/did_core_id
* device_id · string · $ref ./common-ids.schema.json#/$defs/device_id
pattern: ^ak:device:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$
* audience_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* holder_jkt · string
RFC 7638 thumbprint of the DPoP holder key for the handoff or predecessor SessionGrant.
pattern: ^[A-Za-z0-9_-]{43}$
* session_intent_digest · string
Digest of the complete canonical immutable issue or refresh intent.
pattern: ^sha256:[0-9a-f]{64}$
* issued_at · string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
* expires_at · string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
* verification_method · string
DID URL of the accepted device key; its fragment MUST identify device_id and its bare did MUST project to account_id.principal_id.
pattern: ^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$
* signature · string
64-byte raw Ed25519 signature encoded as canonical unpadded base64url.
pattern: ^[A-Za-z0-9_-]{86}$
anyOf · anyOf[1] · oneOf[2] · $ref #/$defs/ActorPrivateEventSubmitOutcome
Closed outcome of ak.self.actor_private_events.command.submit.v1, discriminated by event_kind. accepted_event_id is the event_id of the accepted Event, and an exact retry returns the first stored outcome. Only ak.device.push_route carries the accepted per-route revision its next write must name as expected_server_revision. No RealmCommit exists for these writes.
oneOf · oneOf[0] · object
* event_kind · const "ak.device.push_route"
enum: "ak.device.push_route"
* accepted_event_id · string · $ref #/$defs/EventId
pattern: ^ak:event:[A-Za-z0-9_-]{44}$
* revision · integer
oneOf · oneOf[1] · object
* event_kind · string (enum)
enum: "ak.agent.action_reject" "ak.agent.action_request" "ak.agent.draft.propose"
* accepted_event_id · string · $ref #/$defs/EventId
pattern: ^ak:event:[A-Za-z0-9_-]{44}$
anyOf · anyOf[2] · object · $ref #/$defs/ActorPrivateEventSubmitRequestBody
Request of ak.self.actor_private_events.command.submit.v1: exactly one caller-signed actor-private Event of a kind that has no dedicated submit operation. The service validates the exact Event bytes and MUST NOT rebuild the payload or co-sign. No approval sidecar exists because no approval layer applies to these kinds. zh/models/actor-private-effects.md section 2.1.
* event · object · $ref ./event-envelope.schema.json
Closed producer-signed Event. Shared persistent Events become final only when the current Realm governance Station issues a RealmCommit in the derived Realm, Circle, or Sidecar stream.
allOf · allOf[0] · ?
allOf · allOf[1] · ?
allOf · allOf[2] · ?
allOf · allOf[3] · ?
allOf · allOf[4] · ?
allOf · allOf[5] · $ref #/$defs/registered_admission_shape · $ref #/$defs/registered_admission_shape
allOf · allOf[6] · $ref #/$defs/registered_execution_shape · $ref #/$defs/registered_execution_shape
allOf · allOf[7] · ?
allOf · allOf[8] · ?
allOf · allOf[9] · ?
allOf · allOf[10] · ?
allOf · allOf[11] · ?
allOf · allOf[12] · ?
allOf · allOf[13] · ?
allOf · allOf[14] · ?
allOf · allOf[15] · ?
allOf · allOf[16] · ?
allOf · allOf[17] · ?
allOf · allOf[18] · ?
allOf · allOf[19] · ?
allOf · allOf[20] · ?
allOf · allOf[21] · ?
allOf · allOf[22] · ?
allOf · allOf[23] · ?
allOf · allOf[24] · ?
allOf · allOf[25] · ?
allOf · allOf[26] · ?
allOf · allOf[27] · ?
allOf · allOf[28] · ?
allOf · allOf[29] · ?
allOf · allOf[30] · ?
allOf · allOf[31] · ?
allOf · allOf[32] · ?
allOf · allOf[33] · ?
allOf · allOf[34] · ?
allOf · allOf[35] · ?
allOf · allOf[36] · ?
allOf · allOf[37] · ?
allOf · allOf[38] · ?
allOf · allOf[39] · ?
allOf · allOf[40] · ?
allOf · allOf[41] · ?
allOf · allOf[42] · ?
allOf · allOf[43] · ?
allOf · allOf[44] · ?
allOf · allOf[45] · ?
allOf · allOf[46] · ?
allOf · allOf[47] · ?
allOf · allOf[48] · ?
allOf · allOf[49] · ?
allOf · allOf[50] · ?
allOf · allOf[51] · ?
allOf · allOf[52] · ?
allOf · allOf[53] · ?
allOf · allOf[54] · ?
allOf · allOf[55] · ?
allOf · allOf[56] · ?
allOf · allOf[57] · ?
allOf · allOf[58] · ?
allOf · allOf[59] · ?
allOf · allOf[60] · ?
allOf · allOf[61] · ?
allOf · allOf[62] · ?
allOf · allOf[63] · ?
allOf · allOf[64] · ?
allOf · allOf[65] · ?
allOf · allOf[66] · ?
allOf · allOf[67] · ?
allOf · allOf[68] · ?
allOf · allOf[69] · ?
allOf · allOf[70] · ?
allOf · allOf[71] · ?
allOf · allOf[72] · ?
allOf · allOf[73] · ?
allOf · allOf[74] · ?
allOf · allOf[75] · ?
allOf · allOf[76] · ?
allOf · allOf[77] · ?
allOf · allOf[78] · ?
allOf · allOf[79] · ?
allOf · allOf[80] · ?
allOf · allOf[81] · ?
allOf · allOf[82] · ?
allOf · allOf[83] · ?
allOf · allOf[84] · ?
allOf · allOf[85] · ?
allOf · allOf[86] · ?
allOf · allOf[87] · ?
allOf · allOf[88] · ?
allOf · allOf[89] · ?
allOf · allOf[90] · ?
allOf · allOf[91] · ?
allOf · allOf[92] · ?
allOf · allOf[93] · ?
allOf · allOf[94] · ?
allOf · allOf[95] · ?
allOf · allOf[96] · ?
allOf · allOf[97] · ?
allOf · allOf[98] · ?
allOf · allOf[99] · ?
allOf · allOf[100] · ?
allOf · allOf[101] · ?
allOf · allOf[102] · ?
allOf · allOf[103] · ?
allOf · allOf[104] · ?
allOf · allOf[105] · ?
allOf · allOf[106] · ?
allOf · allOf[107] · ?
allOf · allOf[108] · ?
allOf · allOf[109] · ?
allOf · allOf[110] · ?
allOf · allOf[111] · ?
allOf · allOf[112] · ?
allOf · allOf[113] · ?
allOf · allOf[114] · ?
allOf · allOf[115] · ?
allOf · allOf[116] · ?
allOf · allOf[117] · ?
allOf · allOf[118] · ?
allOf · allOf[119] · ?
allOf · allOf[120] · ?
allOf · allOf[121] · ?
allOf · allOf[122] · ?
allOf · allOf[123] · ?
allOf · allOf[124] · ?
allOf · allOf[125] · ?
allOf · allOf[126] · ?
allOf · allOf[127] · ?
allOf · allOf[128] · ?
allOf · allOf[129] · ?
allOf · allOf[130] · ?
allOf · allOf[131] · ?
allOf · allOf[132] · ?
allOf · allOf[133] · ?
allOf · allOf[134] · ?
allOf · allOf[135] · ?
allOf · allOf[136] · ?
allOf · allOf[137] · ?
allOf · allOf[138] · ?
allOf · allOf[139] · ?
allOf · allOf[140] · ?
* event_id · string · $ref ./common-ids.schema.json#/$defs/event_id
Complete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern: ^ak:event:[A-Za-z0-9_-]{44}$
* kind · string
Standard ak.* Event kinds MUST appear in artifacts/registry/event-kind-registry.json. State convergence is defined by the registered pure reducer over kind + payload; producers do not submit typed current result writes.
pattern: ^ak\.[a-z0-9_]+(\.[a-z0-9_]+)*$
realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* scope_ref · $ref #/$defs/scope_ref · $ref #/$defs/scope_ref
Required producer-signed security scope. The closed union is ordinary existing realm, circle, or native sidecar scope plus the create-only realm_genesis exception. It enters proof.event_digest and E2EE AAD. Reducers independently derive the exact scope from schema-validated payload and accepted references; missing dependencies, nonexistent scope, realm_id mismatch, omitted sidecar_id, substituting circle for sidecar, or any unequal field is fail closed. Sidecar domain Event kinds remain Extension-owned; recognizing this native security shape does not make Kernel interpret the Sidecar reducer. Exact product targets remain inside recipient-visible ciphertext.
* actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind · …
recursion truncated at depth 8; see source schema for full shape
* account_id · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* kind · …
recursion truncated at depth 8; see source schema for full shape
* service_id · …
recursion truncated at depth 8; see source schema for full shape
executed_by · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind · …
recursion truncated at depth 8; see source schema for full shape
* account_id · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* kind · …
recursion truncated at depth 8; see source schema for full shape
* service_id · …
recursion truncated at depth 8; see source schema for full shape
authorization_ref · oneOf[6]
Optional. Required when executed_by is present. It identifies an accepted Grant, delegation Event, DID-document delegation, or one of the closed profile-specific authority constants. The current governance Station evaluates the reference against the target stream's committed state.
oneOf · oneOf[0] · $ref #/$defs/grant_ref · $ref #/$defs/grant_ref
oneOf · oneOf[1] · $ref #/$defs/event_ref · $ref #/$defs/event_ref
oneOf · oneOf[2] · $ref #/$defs/did_delegation_ref · $ref #/$defs/did_delegation_ref
oneOf · oneOf[3] · $ref #/$defs/direct_conversation_participant_authority_ref · $ref #/$defs/direct_conversation_participant_authority_ref
oneOf · oneOf[4] · $ref #/$defs/direct_conversation_bootstrap_authority_ref · $ref #/$defs/direct_conversation_bootstrap_authority_ref
oneOf · oneOf[5] · $ref #/$defs/membership_compensation_delegation_ref · $ref #/$defs/membership_compensation_delegation_ref
applet_id · $ref #/$defs/applet_id · $ref #/$defs/applet_id
Optional signed Applet provenance. Required by ak.profile.applet_* when the Event is introduced by an Applet, Ghost Actor, bridge, or delegated applet path. Enters canonical event bytes and therefore is covered by proof.event_digest. When present, authorization_ref MUST also be present and resolve to a real active registration/capability grant binding this applet_id, registration_epoch, action and resource per zh/extensions/applet-integration.md sections 4, 8 and 11. Service-actor self-signature proves provenance but is not an authorization substitute. Capability-gated actions require a grant covering action/resource. For subject_only operations the referenced grant binds only the exact active install and cannot replace the subject signature, FSM or independent action authority. Service self-authored Events use ActorId.service; the install grant subject MUST be the same exact ActorId.service as its producer; hosting Station and effective scope are verified separately without coercing a Service into an account variant.
external_ref · $ref #/$defs/external_ref · $ref #/$defs/external_ref
Optional signed external provenance reference for Applet / bridge-originated Events. It is covered by event_digest and MUST NOT be carried only in unsigned when used for loop prevention, audit, or external-message idempotency. Must not contain unauthorized external plaintext.
* created_at · $ref #/$defs/canonical_event_timestamp · $ref #/$defs/canonical_event_timestamp
semantic_refs · array<$ref #/$defs/semantic_ref>
Optional semantic refs with role. Omit when there are no semantic references; an explicitly empty array is not canonical. Admission selectors determine any required references. PCR policy recovery has no DID-root anchor reference; its policy/session/replacement-key authority is verified separately.
items · $ref #/$defs/semantic_ref · $ref #/$defs/semantic_ref
* payload · object
* producer_proof · $ref #/$defs/event_proof · $ref #/$defs/event_proof
The Event's sole portable producer proof. Storage receipts are separate objects and never authorize this Event. producer_proof and unsigned remain outside the canonical Event digest. Exact retries preserve the verified producer proof.
anyOf · anyOf[3] · object · $ref #/$defs/AccountCursorRevokeOutcome
* revoked · boolean
expires_at · string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
anyOf · anyOf[4] · object · $ref #/$defs/AccountCursorRevokeRequestBody
* cursor · string
pattern: ^ak:cursor:[A-Za-z0-9_-]+$
* reason_code · string
pattern: ^[a-z][a-z0-9_]{0,63}$
revoke_scope · string (enum)
enum: "this_cursor" "same_device" "same_session"
example: "this_cursor"
anyOf · anyOf[5] · object · $ref #/$defs/AccountLogoutOutcome
* revoked · boolean
Whether a live device session was revoked.
anyOf · anyOf[6] · object · $ref #/$defs/AccountLogoutRequestBody
anyOf · anyOf[7] · object · $ref #/$defs/AuthSessionLogoutOutcome
* grant_chain_terminated · boolean
Whether the grant rotation chain is now unable to refresh, including the already-terminated idempotent case.
* auth_session_logged_out · boolean
Whether the underlying Auth-side browser/auth session is now logged out, including the already-logged-out idempotent case.
anyOf · anyOf[8] · object · $ref #/$defs/AuthSessionLogoutRequestBody
Service-to-service Account Authority to Auth Server request that logs out the Auth-side session owning a ak.session.grant rotation chain.
* grant_jwt · string
Session grant used to locate the Auth-side session and its rotation chain.
logout_request_digest · string
Optional digest of the validated client-visible account /logout request that caused this S2S sub-operation.
pattern: ^(sha256|blake3):[0-9a-f]{64}$
validated_at · string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
reason_code · string (enum)
Reason for logging out the Auth-side session. v1 defines only account_logout for this S2S sub-operation.
enum: "account_logout"
anyOf · anyOf[9] · object · $ref #/$defs/AuthzCheckOutcome
ak.self.authz.read.check.v1 diagnostic/preflight decision. See zh/authz/capabilities.md §18. This response is advisory; canonical Event admission remains authoritative.
* decision · string (enum)
`allow` / `hard_deny` are terminal decisions. `soft_deny` is an evaluated policy soft refusal. `quarantine` / `require_review` are local moderation outcomes. Transient dependency or freshness failures are reported through `freshness_state`, `reason_code`, and `retry_after_ms`, not as policy decision values.
enum: "allow" "soft_deny" "hard_deny" "quarantine" "require_review"
matched_grants · array<object>
items · object
applied_constraints · array<object>
items · object
policy_results · array<object>
items · object
missing_proofs · array<object>
items · object
checkpoint · object
freshness_state · string (enum)
Checkpoint freshness classification for revocation-sensitive decisions; see zh/authz/capabilities.md §18.2.
enum: "fresh" "stale" "unknown"
last_known_checkpoint_age_ms · integer
Age of the newest revocation/auth checkpoint evidence used for this decision. Present when freshness_state is stale or unknown.
authority_status · string (enum)
Coarse status of the current governance Station and committed-stream source used to diagnose stale or unknown revocation freshness.
enum: "fresh" "lagging" "unreachable" "unknown"
cache_expires_at · string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
reason_code · string
Registered reason code. High-risk stale or unknown revocation freshness returns revocation_freshness_unknown.
pattern: ^[a-z][a-z0-9_]{0,63}$
retry_after_ms · integer
Set when `freshness_state ∈ {stale,unknown}` or a retryable `reason_code` is present; client SHOULD back off this amount before retry.
obligations · array<object>
Additional local preflight obligations the caller MUST satisfy before the action proceeds.
items · object
anyOf · anyOf[10] · object · $ref #/$defs/AuthzCheckRequestBody
ak.self.authz.read.check.v1 advisory local authorization preflight. It is never a cross-service authorization fact and cannot replace the current governance Station's admission decision.
* actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind · const "account"
enum: "account"
* account_id · $ref #/$defs/account_id · $ref #/$defs/account_id
oneOf · oneOf[1] · object
* kind · const "service"
enum: "service"
* service_id · $ref #/$defs/did_core_id · $ref #/$defs/did_core_id
* action · string
Capability action id (e.g. `ak.strand.update`).
resource · object
Optional resource selector (Realm / Strand / Space / Morph / etc.).
context · object
Optional decision context — claim presentations, checkpoint reference, request metadata.
anyOf · anyOf[11] · object · $ref #/$defs/BlobPresignOutcome
* url · string (uri) · format=uri
Fully-qualified URL clients can pass to browser primitives. Contains the `presign` query parameter, `blob_ref`, and a presign envelope bound to `realm_id` for Realm-owned blobs.
pattern: ^https?://
* expires_at · string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
purpose · string
Echo of the issued `purpose`.
anyOf · anyOf[12] · object · $ref #/$defs/BlobPresignRequestBody
* blob_ref · string · $ref ./common-ids.schema.json#/$defs/blob_ref
Content-addressed reference to exact Blob bytes. The embedded suite and digest are the sole wire commitment to those bytes; sibling content/ciphertext digest mirrors are forbidden.
pattern: ^ak:blob:(?:sha256|blake3):[0-9a-f]{64}$
realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
max_age_seconds · integer
Client-requested TTL upper bound. Server clamps to the smaller of this value, the issuing grant's `blob_presign_max_ttl_seconds` constraint, and the deployment-level cap.
purpose · string (enum)
Intended rendering / download mode. Servers MAY apply purpose-specific Content-Disposition or rate limits.
enum: "media_inline" "thumbnail" "download"
anyOf · anyOf[13] · object · $ref #/$defs/CallMediaTokenExchangeOutcome
allOf · allOf[0] · ?
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* call_id · string
pattern: ^ak:call:[A-Za-z0-9_-]{44}$
* actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind · const "account"
enum: "account"
* account_id · $ref #/$defs/account_id · $ref #/$defs/account_id
oneOf · oneOf[1] · object
* kind · const "service"
enum: "service"
* service_id · $ref #/$defs/did_core_id · $ref #/$defs/did_core_id
* device_id · string
pattern: ^ak:device:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$
* focus_id · string
pattern: ^(?!ak:)
* connect_url · string (uri) · format=uri
pattern: ^(https|wss)://
* backend_token · ?
Closed branch selected by backend_kind: arkret_native uses the typed signature object; every other v1 backend uses a non-empty opaque string.
* participant_id · string
SFU-local short handle, scope `(call_id, focus_id, sfu_did)`. UUIDv7-form rtc_participant typed ID.
pattern: ^ak:rtc_participant:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$
* participant_binding · object · $ref ./event-payload.schema.json#/$defs/participant_binding
Token issuer's signed commitment over (realm_id, call_id, focus_id, actor_id, device_id, participant_id, expires_at) for a media participant. See crypto-media/media-service-binding.md §3 and crypto-media/call-state.md §4.1. v1 uses the single scheme ak.media.participant_binding.v1.
* expires_at · $ref #/$defs/timestamp · $ref #/$defs/timestamp
* issuer_kid · string
DID URL (with fragment) of the token issuer service signing key. MUST resolve to a service DID present in the current-epoch ak.realm.media_service.service_id.
pattern: ^did:[a-z0-9]+:[^\s?]+#[^\s#?]+$
* sig · $ref #/$defs/non_empty_string · $ref #/$defs/non_empty_string
* expires_at · string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
* backend_kind · string (enum)
Backend binding type identifier (livekit / arkret_native / etc.).
enum: "livekit" "mediasoup" "janus" "arkret_native" "moq_relay"
anyOf · anyOf[14] · object · $ref #/$defs/CallMediaTokenExchangeRequestBody
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* call_id · string
pattern: ^ak:call:[A-Za-z0-9_-]{44}$
* actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind · const "account"
enum: "account"
* account_id · $ref #/$defs/account_id · $ref #/$defs/account_id
oneOf · oneOf[1] · object
* kind · const "service"
enum: "service"
* service_id · $ref #/$defs/did_core_id · $ref #/$defs/did_core_id
* device_id · string
Stable protocol endpoint identifier. REQUIRED for agent_key_proof and covered by request_canonical_digest; the Account Authority MUST persist and return the same value in the issued grant so Stations can bind MLS KeyPackage ownership, Welcome routing, consume/revoke operations, refresh, and restart recovery to one endpoint. It MUST NOT be derived from a session or grant id.
pattern: ^ak:device:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$
* focus_id · string
pattern: ^(?!ak:)
capability_refs · array<string>
items · string
pattern: ^ak:grant:[A-Za-z0-9_-]{44}$
desired_media · object
audio · boolean
video · boolean
screen · boolean
anyOf · anyOf[15] · object · $ref #/$defs/DeviceMessagesAckOutcome
* pruned_count · integer
Number of recipient deliveries acknowledged by this token: DeviceMessage rows deleted plus Welcome rows marked delivered and retained for audit; zero is legal for a repeated or older token.
anyOf · anyOf[16] · object · $ref #/$defs/DeviceMessagesAckRequestBody
* ack_token · string
Acknowledgement token previously issued to the same authenticated recipient endpoint by account subscribe or the recipient-delivery list. It cumulatively prunes both DeviceMessage and MlsWelcomeDelivery queue items through the bound position, only after every covered item was durably processed. Unknown / expired / cross-bound tokens MUST be rejected with param_invalid (reason invalid_ack_token) without deleting anything. Naturally idempotent; no Idempotency-Key required.
anyOf · anyOf[17] · object · $ref #/$defs/DeviceMessagesGetOutcome
allOf · allOf[0] · ?
* deliveries · array<$ref ./account-subscribe-frame.schema.json#/$defs/recipient_delivery>
Ordered recipient-private queue items, each discriminated as an unchanged DeviceMessageEnvelope or MlsWelcomeDelivery. These are not shared Event Envelope objects.
items · oneOf[2] · $ref ./account-subscribe-frame.schema.json#/$defs/recipient_delivery
One exact recipient-private queue item. The discriminator selects an unchanged DeviceMessageEnvelope or producer-signed MlsWelcomeDelivery; neither payload is rewritten into the other.
oneOf · oneOf[0] · object
* delivery_kind · …
recursion truncated at depth 8; see source schema for full shape
* device_message · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* delivery_kind · …
recursion truncated at depth 8; see source schema for full shape
* mls_welcome · …
recursion truncated at depth 8; see source schema for full shape
ack_token · string
Server-issued opaque acknowledgement token, REQUIRED whenever deliveries[] is non-empty. Covers both delivery kinds in this page and earlier items for the authenticated recipient endpoint. Queue deletion happens only through ak.self.device_messages.command.ack.v1 with this token, never through the after= read cursor (client-sync.md §10.1).
next_cursor · string
Read-only continuation position; advancing it MUST NOT delete queued messages.
* has_more · boolean
limited · boolean
lost · boolean
SHOULD be true only for a durably evidenced historical gap or failure since this recipient endpoint's last acknowledged position; normal expiry and capacity MUST NOT delete unacknowledged deliveries of either kind. Clients MUST re-establish MLS/key readiness when true.
anyOf · anyOf[18] · object · $ref #/$defs/DeviceMessagesSendOutcome
* delivered · object
Principal-id to device-id map for messages accepted for delivery.
* unknown_devices · object
Principal-id to device-id map for recipient targets that are not deliverable. Membership alone is the whole result: unknown, revoked, fenced or otherwise undeliverable devices are indistinguishable. A sender-side invalid expires_at never lands here; it fails the whole request.
anyOf · anyOf[19] · object · $ref #/$defs/DeviceMessagesSendRequestBody
* messages · object
Station-local did_core_id -> device_id map. The authenticated addressed Station supplies the AccountId Station component; this body carries no cross-Station route and MUST NOT use ActorId JSON as a key.
anyOf · anyOf[20] · object · $ref #/$defs/DidOperationSubmitOutcome
* status · string (enum)
enum: "accepted" "duplicate" "pending"
* did · string · $ref ./common-ids.schema.json#/$defs/did
Canonical bare DID used for registration, DID method resolution and owner-published current resolution. It contains no path, query or fragment and MUST project through the registered method adapter to exactly one did_core_id.
pattern: ^did:[a-z0-9]+:[^\s/?#]+$
* accepted_at · string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
seq · integer
New method sequence number when available.
* operation_ref · string
Exact method-native immutable operation identifier. For did:webvh this is did + "?versionId=" + the submitted entry versionId. The authenticated response acknowledges the exact complete submitted operation, including proofs; accepted/duplicate MUST match the locally frozen typed request and its method-native version and sequence. A registry MUST NOT normalize or replace accepted entry bytes. A duplicate returns the original result for the same bytes.
receipts · array<object>
items · object
anyOf · anyOf[21] · object · $ref #/$defs/DidOperationSubmitRequestBody
* did · string · $ref ./common-ids.schema.json#/$defs/did
Canonical bare DID used for registration, DID method resolution and owner-published current resolution. It contains no path, query or fragment and MUST project through the registered method adapter to exactly one did_core_id.
pattern: ^did:[a-z0-9]+:[^\s/?#]+$
* did_method · string
DID method discriminator without the did: prefix (e.g. web, webvh, key). It MUST exactly equal the method component of did; verifiers dispatch method-specific validation only after that equality check.
pattern: ^[a-z0-9]+$
seq · integer
Optional method sequence number when the DID method exposes one.
prev_event_digest · string
Optional previous operation hash / key-log head, when required by the DID method.
pattern: ^sha256:[0-9a-f]{64}$
* operation · object
Complete DID method-native operation, including every controller/update/recovery proof required by that method. This is not a generic JSON Patch. The selected adapter MUST validate the immutable native operation and its full history before any state mutation; transport authentication never substitutes for method-native control proof.
anyOf · anyOf[22] · oneOf[2] · $ref #/$defs/DirectConversationFoundingAuthorityEvidence
Closed XOR authorization evidence for one Direct Conversation founding unit, matching the two registered ak.realm.create admission variants. The human branch feeds direct_conversation_genesis; the controller_agent branch feeds direct_conversation_agent_genesis. Carrying both, neither, or mixed branch fields rejects the whole unit.
oneOf · oneOf[0] · object
* kind · const "human"
enum: "human"
* contact_round_evidence · object · $ref ./contact-operations.schema.json#/$defs/contact_round_evidence_bundle
Portable evidence for the pair's current Contact round. The verifier re-derives founder from the root Contact round, never from the current round.
allOf · allOf[0] · ?
* contact_round_id · string · $ref ./principal-operations.schema.json#/$defs/digest
pattern: ^sha256:[0-9a-f]{64}$
previous_terminal_contact_round_id · string · $ref ./principal-operations.schema.json#/$defs/digest
Absent only for a root Contact round. On recontact it is copied from every signed request fact and request acceptance receipt in this bundle and points to the immediately preceding terminal round. The bundle field is derived convenience, never independent authority.
pattern: ^sha256:[0-9a-f]{64}$
* contact_round · $ref #/$defs/contact_round · $ref #/$defs/contact_round
* request_receipts · array<$ref #/$defs/request_acceptance_receipt>
items · …
recursion truncated at depth 8; see source schema for full shape
normal_response_receipt · $ref #/$defs/normal_response_acceptance_receipt · $ref #/$defs/normal_response_acceptance_receipt
glare_concurrency_attestations · array<$ref #/$defs/glare_concurrency_attestation>
items · …
recursion truncated at depth 8; see source schema for full shape
* current_proofs · array<$ref #/$defs/contact_current_proof>
items · …
recursion truncated at depth 8; see source schema for full shape
continuity_checkpoint · $ref #/$defs/bilateral_continuity_checkpoint · $ref #/$defs/bilateral_continuity_checkpoint
Latest mutually signed compacted prefix for this lineage. Its presence changes the chain terminator from the root round to covered_through_contact_round_id; it never changes the root basis or participant authority pair.
* contact_round_continuity_chains · array<$ref ./contact-operations.schema.json#/$defs/contact_round_evidence_bundle>
Ordered tombstone/recontact predecessors from the current Contact round back to the pair's unique root Contact round, each linked by previous_terminal_contact_round_id. An empty array means the current round is itself the root. A break, a cycle, multiple roots or two directional proofs yielding different roots reject the unit.
items · object · $ref ./contact-operations.schema.json#/$defs/contact_round_evidence_bundle
allOf · allOf[0] · …
recursion truncated at depth 8; see source schema for full shape
* contact_round_id · …
recursion truncated at depth 8; see source schema for full shape
previous_terminal_contact_round_id · …
recursion truncated at depth 8; see source schema for full shape
* contact_round · …
recursion truncated at depth 8; see source schema for full shape
* request_receipts · …
recursion truncated at depth 8; see source schema for full shape
normal_response_receipt · …
recursion truncated at depth 8; see source schema for full shape
glare_concurrency_attestations · …
recursion truncated at depth 8; see source schema for full shape
* current_proofs · …
recursion truncated at depth 8; see source schema for full shape
continuity_checkpoint · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* kind · const "controller_agent"
enum: "controller_agent"
* agent_provision_ref · string · $ref ./principal-operations.schema.json#/$defs/event_id
Complete identity of the accepted Agent provision Event. Its digest is derived by decoding this suite-tagged full-digest EventId; no parallel agent_provision_digest is carried.
pattern: ^ak:event:[A-Za-z0-9_-]{44}$
* controller_binding_digest · string · $ref ./principal-operations.schema.json#/$defs/digest
pattern: ^sha256:[0-9a-f]{64}$
anyOf · anyOf[23] · object · $ref #/$defs/EventAdmissionSubmission
One exact producer-signed Event submitted to the current governance Station, plus the approval signatures required by a grant, Realm governance or List WIP policy for the Event action or for this registered submit operation. There are no RealmCommit, typed current result, offline-lease or proof-bundle sidecars. approval_signatures is the only sidecar and it is deliberately outside event: the Event bytes and event_id are finished before any approval is signed, so attaching them never changes the Event (zh/authz/constraint-schema.md section 9.2.5).
* event · object · $ref ./event-envelope.schema.json
Closed producer-signed Event. Shared persistent Events become final only when the current Realm governance Station issues a RealmCommit in the derived Realm, Circle, or Sidecar stream.
allOf · allOf[0] · ?
allOf · allOf[1] · ?
allOf · allOf[2] · ?
allOf · allOf[3] · ?
allOf · allOf[4] · ?
allOf · allOf[5] · $ref #/$defs/registered_admission_shape · $ref #/$defs/registered_admission_shape
allOf · allOf[6] · $ref #/$defs/registered_execution_shape · $ref #/$defs/registered_execution_shape
allOf · allOf[7] · ?
allOf · allOf[8] · ?
allOf · allOf[9] · ?
allOf · allOf[10] · ?
allOf · allOf[11] · ?
allOf · allOf[12] · ?
allOf · allOf[13] · ?
allOf · allOf[14] · ?
allOf · allOf[15] · ?
allOf · allOf[16] · ?
allOf · allOf[17] · ?
allOf · allOf[18] · ?
allOf · allOf[19] · ?
allOf · allOf[20] · ?
allOf · allOf[21] · ?
allOf · allOf[22] · ?
allOf · allOf[23] · ?
allOf · allOf[24] · ?
allOf · allOf[25] · ?
allOf · allOf[26] · ?
allOf · allOf[27] · ?
allOf · allOf[28] · ?
allOf · allOf[29] · ?
allOf · allOf[30] · ?
allOf · allOf[31] · ?
allOf · allOf[32] · ?
allOf · allOf[33] · ?
allOf · allOf[34] · ?
allOf · allOf[35] · ?
allOf · allOf[36] · ?
allOf · allOf[37] · ?
allOf · allOf[38] · ?
allOf · allOf[39] · ?
allOf · allOf[40] · ?
allOf · allOf[41] · ?
allOf · allOf[42] · ?
allOf · allOf[43] · ?
allOf · allOf[44] · ?
allOf · allOf[45] · ?
allOf · allOf[46] · ?
allOf · allOf[47] · ?
allOf · allOf[48] · ?
allOf · allOf[49] · ?
allOf · allOf[50] · ?
allOf · allOf[51] · ?
allOf · allOf[52] · ?
allOf · allOf[53] · ?
allOf · allOf[54] · ?
allOf · allOf[55] · ?
allOf · allOf[56] · ?
allOf · allOf[57] · ?
allOf · allOf[58] · ?
allOf · allOf[59] · ?
allOf · allOf[60] · ?
allOf · allOf[61] · ?
allOf · allOf[62] · ?
allOf · allOf[63] · ?
allOf · allOf[64] · ?
allOf · allOf[65] · ?
allOf · allOf[66] · ?
allOf · allOf[67] · ?
allOf · allOf[68] · ?
allOf · allOf[69] · ?
allOf · allOf[70] · ?
allOf · allOf[71] · ?
allOf · allOf[72] · ?
allOf · allOf[73] · ?
allOf · allOf[74] · ?
allOf · allOf[75] · ?
allOf · allOf[76] · ?
allOf · allOf[77] · ?
allOf · allOf[78] · ?
allOf · allOf[79] · ?
allOf · allOf[80] · ?
allOf · allOf[81] · ?
allOf · allOf[82] · ?
allOf · allOf[83] · ?
allOf · allOf[84] · ?
allOf · allOf[85] · ?
allOf · allOf[86] · ?
allOf · allOf[87] · ?
allOf · allOf[88] · ?
allOf · allOf[89] · ?
allOf · allOf[90] · ?
allOf · allOf[91] · ?
allOf · allOf[92] · ?
allOf · allOf[93] · ?
allOf · allOf[94] · ?
allOf · allOf[95] · ?
allOf · allOf[96] · ?
allOf · allOf[97] · ?
allOf · allOf[98] · ?
allOf · allOf[99] · ?
allOf · allOf[100] · ?
allOf · allOf[101] · ?
allOf · allOf[102] · ?
allOf · allOf[103] · ?
allOf · allOf[104] · ?
allOf · allOf[105] · ?
allOf · allOf[106] · ?
allOf · allOf[107] · ?
allOf · allOf[108] · ?
allOf · allOf[109] · ?
allOf · allOf[110] · ?
allOf · allOf[111] · ?
allOf · allOf[112] · ?
allOf · allOf[113] · ?
allOf · allOf[114] · ?
allOf · allOf[115] · ?
allOf · allOf[116] · ?
allOf · allOf[117] · ?
allOf · allOf[118] · ?
allOf · allOf[119] · ?
allOf · allOf[120] · ?
allOf · allOf[121] · ?
allOf · allOf[122] · ?
allOf · allOf[123] · ?
allOf · allOf[124] · ?
allOf · allOf[125] · ?
allOf · allOf[126] · ?
allOf · allOf[127] · ?
allOf · allOf[128] · ?
allOf · allOf[129] · ?
allOf · allOf[130] · ?
allOf · allOf[131] · ?
allOf · allOf[132] · ?
allOf · allOf[133] · ?
allOf · allOf[134] · ?
allOf · allOf[135] · ?
allOf · allOf[136] · ?
allOf · allOf[137] · ?
allOf · allOf[138] · ?
allOf · allOf[139] · ?
allOf · allOf[140] · ?
* event_id · string · $ref ./common-ids.schema.json#/$defs/event_id
Complete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern: ^ak:event:[A-Za-z0-9_-]{44}$
* kind · string
Standard ak.* Event kinds MUST appear in artifacts/registry/event-kind-registry.json. State convergence is defined by the registered pure reducer over kind + payload; producers do not submit typed current result writes.
pattern: ^ak\.[a-z0-9_]+(\.[a-z0-9_]+)*$
realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* scope_ref · $ref #/$defs/scope_ref · $ref #/$defs/scope_ref
Required producer-signed security scope. The closed union is ordinary existing realm, circle, or native sidecar scope plus the create-only realm_genesis exception. It enters proof.event_digest and E2EE AAD. Reducers independently derive the exact scope from schema-validated payload and accepted references; missing dependencies, nonexistent scope, realm_id mismatch, omitted sidecar_id, substituting circle for sidecar, or any unequal field is fail closed. Sidecar domain Event kinds remain Extension-owned; recognizing this native security shape does not make Kernel interpret the Sidecar reducer. Exact product targets remain inside recipient-visible ciphertext.
* actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind · …
recursion truncated at depth 8; see source schema for full shape
* account_id · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* kind · …
recursion truncated at depth 8; see source schema for full shape
* service_id · …
recursion truncated at depth 8; see source schema for full shape
executed_by · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind · …
recursion truncated at depth 8; see source schema for full shape
* account_id · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* kind · …
recursion truncated at depth 8; see source schema for full shape
* service_id · …
recursion truncated at depth 8; see source schema for full shape
authorization_ref · oneOf[6]
Optional. Required when executed_by is present. It identifies an accepted Grant, delegation Event, DID-document delegation, or one of the closed profile-specific authority constants. The current governance Station evaluates the reference against the target stream's committed state.
oneOf · oneOf[0] · $ref #/$defs/grant_ref · $ref #/$defs/grant_ref
oneOf · oneOf[1] · $ref #/$defs/event_ref · $ref #/$defs/event_ref
oneOf · oneOf[2] · $ref #/$defs/did_delegation_ref · $ref #/$defs/did_delegation_ref
oneOf · oneOf[3] · $ref #/$defs/direct_conversation_participant_authority_ref · $ref #/$defs/direct_conversation_participant_authority_ref
oneOf · oneOf[4] · $ref #/$defs/direct_conversation_bootstrap_authority_ref · $ref #/$defs/direct_conversation_bootstrap_authority_ref
oneOf · oneOf[5] · $ref #/$defs/membership_compensation_delegation_ref · $ref #/$defs/membership_compensation_delegation_ref
applet_id · $ref #/$defs/applet_id · $ref #/$defs/applet_id
Optional signed Applet provenance. Required by ak.profile.applet_* when the Event is introduced by an Applet, Ghost Actor, bridge, or delegated applet path. Enters canonical event bytes and therefore is covered by proof.event_digest. When present, authorization_ref MUST also be present and resolve to a real active registration/capability grant binding this applet_id, registration_epoch, action and resource per zh/extensions/applet-integration.md sections 4, 8 and 11. Service-actor self-signature proves provenance but is not an authorization substitute. Capability-gated actions require a grant covering action/resource. For subject_only operations the referenced grant binds only the exact active install and cannot replace the subject signature, FSM or independent action authority. Service self-authored Events use ActorId.service; the install grant subject MUST be the same exact ActorId.service as its producer; hosting Station and effective scope are verified separately without coercing a Service into an account variant.
external_ref · $ref #/$defs/external_ref · $ref #/$defs/external_ref
Optional signed external provenance reference for Applet / bridge-originated Events. It is covered by event_digest and MUST NOT be carried only in unsigned when used for loop prevention, audit, or external-message idempotency. Must not contain unauthorized external plaintext.
* created_at · $ref #/$defs/canonical_event_timestamp · $ref #/$defs/canonical_event_timestamp
semantic_refs · array<$ref #/$defs/semantic_ref>
Optional semantic refs with role. Omit when there are no semantic references; an explicitly empty array is not canonical. Admission selectors determine any required references. PCR policy recovery has no DID-root anchor reference; its policy/session/replacement-key authority is verified separately.
items · $ref #/$defs/semantic_ref · $ref #/$defs/semantic_ref
* payload · object
* producer_proof · $ref #/$defs/event_proof · $ref #/$defs/event_proof
The Event's sole portable producer proof. Storage receipts are separate objects and never authorize this Event. producer_proof and unsigned remain outside the canonical Event digest. Exact retries preserve the verified producer proof.
approval_signatures · array<$ref ./approval-signature.schema.json>
One ak.schema.approval_signature.v1 object per approver. An event-target signature binds approval_target.event_id equal to event.event_id. An operation-target signature is allowed only when capability-action-registry.json resolves its action to this exact carrier operation and binds request_canonical_digest to the original typed request with approval_signatures omitted. Every ingress that wraps EventAdmissionSubmission -- ordinary self submit, batch submission, control transactions, facade hand-off -- reuses this one field and MUST NOT define its own DTO. The array is omitted when no approval layer demands evidence; it MUST NOT be present and empty. The governance Station persists the evidence, the verification basis, the nonce consumption and the binding to this submission inside the same atomic acceptance transaction, and the shared Realm Event store keeps the original Event bytes unchanged.
items · object · $ref ./approval-signature.schema.json
The single approval evidence type of v1 (zh/authz/constraint-schema.md section 9.2). One approver signs one exact target: either a fully authored Event that has not been submitted yet, or the original typed RequestBody of one operation whose evidence carrier is registered in capability-action-registry.json. The object is not an Event, never enters Realm history, and MUST NOT be written into an EventEnvelope, a signed payload or an Event semantic_refs[] entry. It travels in the carrier registered for the approved action. It proves that an approver approved that target; it proves nothing about the initiator's own authority.
* input · $ref #/$defs/approval_signature_input · $ref #/$defs/approval_signature_input
* proof · $ref #/$defs/approval_signature_proof · $ref #/$defs/approval_signature_proof
anyOf · anyOf[24] · object · $ref #/$defs/EventDeliveryStatusOutcome
Complete frozen target set for one visible Event. Rows are sorted byte-wise by unique opaque target_id. Consumers derive the pending count by counting pending_route and pending_delivery rows, and derive aggregate state as pending iff that count is non-zero.
* event_id · string · $ref #/$defs/EventId
pattern: ^ak:event:[A-Za-z0-9_-]{44}$
* targets · array<$ref #/$defs/EventDeliveryTargetStatus>
items · object · $ref #/$defs/EventDeliveryTargetStatus
Authorized projection of one frozen Realm fanout target. target_id is opaque and stable. service_id is present only when the caller can currently read at least one exact joined-member ActorId that contributed the target.
* target_id · string
Service-generated opaque target identifier. It MUST NOT encode the target service DID.
pattern: ^[A-Za-z0-9][A-Za-z0-9_-]{15,127}$
* status · string (enum) · $ref #/$defs/EventDeliveryTargetState
Closed lifecycle for one frozen distinct Realm fanout target. Authority loss is terminal and a later rejoin never revives the old target.
enum: "pending_route" "pending_delivery" "delivered" "cancelled_authority_lost"
service_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
anyOf · anyOf[25] · object · $ref #/$defs/EventDeliveryStatusRequestBody
Authenticated, non-enumerating request for the durable fanout state of one caller-visible accepted Event.
* event_id · string · $ref #/$defs/EventId
pattern: ^ak:event:[A-Za-z0-9_-]{44}$
anyOf · anyOf[26] · object · $ref #/$defs/EventSubmitEnvelope
Closed producer-signed Event. Shared persistent Events become final only when the current Realm governance Station issues a RealmCommit in the derived Realm, Circle, or Sidecar stream.
allOf · allOf[0] · ?
allOf · allOf[1] · ?
allOf · allOf[2] · ?
allOf · allOf[3] · ?
allOf · allOf[4] · ?
allOf · allOf[5] · $ref #/$defs/registered_admission_shape · $ref #/$defs/registered_admission_shape
allOf · allOf[6] · $ref #/$defs/registered_execution_shape · $ref #/$defs/registered_execution_shape
allOf · allOf[7] · ?
allOf · allOf[8] · ?
allOf · allOf[9] · ?
allOf · allOf[10] · ?
allOf · allOf[11] · ?
allOf · allOf[12] · ?
allOf · allOf[13] · ?
allOf · allOf[14] · ?
allOf · allOf[15] · ?
allOf · allOf[16] · ?
allOf · allOf[17] · ?
allOf · allOf[18] · ?
allOf · allOf[19] · ?
allOf · allOf[20] · ?
allOf · allOf[21] · ?
allOf · allOf[22] · ?
allOf · allOf[23] · ?
allOf · allOf[24] · ?
allOf · allOf[25] · ?
allOf · allOf[26] · ?
allOf · allOf[27] · ?
allOf · allOf[28] · ?
allOf · allOf[29] · ?
allOf · allOf[30] · ?
allOf · allOf[31] · ?
allOf · allOf[32] · ?
allOf · allOf[33] · ?
allOf · allOf[34] · ?
allOf · allOf[35] · ?
allOf · allOf[36] · ?
allOf · allOf[37] · ?
allOf · allOf[38] · ?
allOf · allOf[39] · ?
allOf · allOf[40] · ?
allOf · allOf[41] · ?
allOf · allOf[42] · ?
allOf · allOf[43] · ?
allOf · allOf[44] · ?
allOf · allOf[45] · ?
allOf · allOf[46] · ?
allOf · allOf[47] · ?
allOf · allOf[48] · ?
allOf · allOf[49] · ?
allOf · allOf[50] · ?
allOf · allOf[51] · ?
allOf · allOf[52] · ?
allOf · allOf[53] · ?
allOf · allOf[54] · ?
allOf · allOf[55] · ?
allOf · allOf[56] · ?
allOf · allOf[57] · ?
allOf · allOf[58] · ?
allOf · allOf[59] · ?
allOf · allOf[60] · ?
allOf · allOf[61] · ?
allOf · allOf[62] · ?
allOf · allOf[63] · ?
allOf · allOf[64] · ?
allOf · allOf[65] · ?
allOf · allOf[66] · ?
allOf · allOf[67] · ?
allOf · allOf[68] · ?
allOf · allOf[69] · ?
allOf · allOf[70] · ?
allOf · allOf[71] · ?
allOf · allOf[72] · ?
allOf · allOf[73] · ?
allOf · allOf[74] · ?
allOf · allOf[75] · ?
allOf · allOf[76] · ?
allOf · allOf[77] · ?
allOf · allOf[78] · ?
allOf · allOf[79] · ?
allOf · allOf[80] · ?
allOf · allOf[81] · ?
allOf · allOf[82] · ?
allOf · allOf[83] · ?
allOf · allOf[84] · ?
allOf · allOf[85] · ?
allOf · allOf[86] · ?
allOf · allOf[87] · ?
allOf · allOf[88] · ?
allOf · allOf[89] · ?
allOf · allOf[90] · ?
allOf · allOf[91] · ?
allOf · allOf[92] · ?
allOf · allOf[93] · ?
allOf · allOf[94] · ?
allOf · allOf[95] · ?
allOf · allOf[96] · ?
allOf · allOf[97] · ?
allOf · allOf[98] · ?
allOf · allOf[99] · ?
allOf · allOf[100] · ?
allOf · allOf[101] · ?
allOf · allOf[102] · ?
allOf · allOf[103] · ?
allOf · allOf[104] · ?
allOf · allOf[105] · ?
allOf · allOf[106] · ?
allOf · allOf[107] · ?
allOf · allOf[108] · ?
allOf · allOf[109] · ?
allOf · allOf[110] · ?
allOf · allOf[111] · ?
allOf · allOf[112] · ?
allOf · allOf[113] · ?
allOf · allOf[114] · ?
allOf · allOf[115] · ?
allOf · allOf[116] · ?
allOf · allOf[117] · ?
allOf · allOf[118] · ?
allOf · allOf[119] · ?
allOf · allOf[120] · ?
allOf · allOf[121] · ?
allOf · allOf[122] · ?
allOf · allOf[123] · ?
allOf · allOf[124] · ?
allOf · allOf[125] · ?
allOf · allOf[126] · ?
allOf · allOf[127] · ?
allOf · allOf[128] · ?
allOf · allOf[129] · ?
allOf · allOf[130] · ?
allOf · allOf[131] · ?
allOf · allOf[132] · ?
allOf · allOf[133] · ?
allOf · allOf[134] · ?
allOf · allOf[135] · ?
allOf · allOf[136] · ?
allOf · allOf[137] · ?
allOf · allOf[138] · ?
allOf · allOf[139] · ?
allOf · allOf[140] · ?
* event_id · string · $ref ./common-ids.schema.json#/$defs/event_id
Complete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern: ^ak:event:[A-Za-z0-9_-]{44}$
* kind · string
Standard ak.* Event kinds MUST appear in artifacts/registry/event-kind-registry.json. State convergence is defined by the registered pure reducer over kind + payload; producers do not submit typed current result writes.
pattern: ^ak\.[a-z0-9_]+(\.[a-z0-9_]+)*$
realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* scope_ref · $ref #/$defs/scope_ref · $ref #/$defs/scope_ref
Required producer-signed security scope. The closed union is ordinary existing realm, circle, or native sidecar scope plus the create-only realm_genesis exception. It enters proof.event_digest and E2EE AAD. Reducers independently derive the exact scope from schema-validated payload and accepted references; missing dependencies, nonexistent scope, realm_id mismatch, omitted sidecar_id, substituting circle for sidecar, or any unequal field is fail closed. Sidecar domain Event kinds remain Extension-owned; recognizing this native security shape does not make Kernel interpret the Sidecar reducer. Exact product targets remain inside recipient-visible ciphertext.
* actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind · const "account"
enum: "account"
* account_id · $ref #/$defs/account_id · $ref #/$defs/account_id
oneOf · oneOf[1] · object
* kind · const "service"
enum: "service"
* service_id · $ref #/$defs/did_core_id · $ref #/$defs/did_core_id
executed_by · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind · const "account"
enum: "account"
* account_id · $ref #/$defs/account_id · $ref #/$defs/account_id
oneOf · oneOf[1] · object
* kind · const "service"
enum: "service"
* service_id · $ref #/$defs/did_core_id · $ref #/$defs/did_core_id
authorization_ref · oneOf[6]
Optional. Required when executed_by is present. It identifies an accepted Grant, delegation Event, DID-document delegation, or one of the closed profile-specific authority constants. The current governance Station evaluates the reference against the target stream's committed state.
oneOf · oneOf[0] · $ref #/$defs/grant_ref · $ref #/$defs/grant_ref
oneOf · oneOf[1] · $ref #/$defs/event_ref · $ref #/$defs/event_ref
oneOf · oneOf[2] · $ref #/$defs/did_delegation_ref · $ref #/$defs/did_delegation_ref
oneOf · oneOf[3] · $ref #/$defs/direct_conversation_participant_authority_ref · $ref #/$defs/direct_conversation_participant_authority_ref
oneOf · oneOf[4] · $ref #/$defs/direct_conversation_bootstrap_authority_ref · $ref #/$defs/direct_conversation_bootstrap_authority_ref
oneOf · oneOf[5] · $ref #/$defs/membership_compensation_delegation_ref · $ref #/$defs/membership_compensation_delegation_ref
applet_id · $ref #/$defs/applet_id · $ref #/$defs/applet_id
Optional signed Applet provenance. Required by ak.profile.applet_* when the Event is introduced by an Applet, Ghost Actor, bridge, or delegated applet path. Enters canonical event bytes and therefore is covered by proof.event_digest. When present, authorization_ref MUST also be present and resolve to a real active registration/capability grant binding this applet_id, registration_epoch, action and resource per zh/extensions/applet-integration.md sections 4, 8 and 11. Service-actor self-signature proves provenance but is not an authorization substitute. Capability-gated actions require a grant covering action/resource. For subject_only operations the referenced grant binds only the exact active install and cannot replace the subject signature, FSM or independent action authority. Service self-authored Events use ActorId.service; the install grant subject MUST be the same exact ActorId.service as its producer; hosting Station and effective scope are verified separately without coercing a Service into an account variant.
external_ref · $ref #/$defs/external_ref · $ref #/$defs/external_ref
Optional signed external provenance reference for Applet / bridge-originated Events. It is covered by event_digest and MUST NOT be carried only in unsigned when used for loop prevention, audit, or external-message idempotency. Must not contain unauthorized external plaintext.
* created_at · $ref #/$defs/canonical_event_timestamp · $ref #/$defs/canonical_event_timestamp
semantic_refs · array<$ref #/$defs/semantic_ref>
Optional semantic refs with role. Omit when there are no semantic references; an explicitly empty array is not canonical. Admission selectors determine any required references. PCR policy recovery has no DID-root anchor reference; its policy/session/replacement-key authority is verified separately.
items · $ref #/$defs/semantic_ref · $ref #/$defs/semantic_ref
* payload · object
* producer_proof · $ref #/$defs/event_proof · $ref #/$defs/event_proof
The Event's sole portable producer proof. Storage receipts are separate objects and never authorize this Event. producer_proof and unsigned remain outside the canonical Event digest. Exact retries preserve the verified producer proof.
anyOf · anyOf[27] · object · $ref #/$defs/EventsSubmitBatchRequestBody
Legacy-named typed array retained only as the nested prepared_event_unit request in security-transaction.schema.json. It is not an ak.self.events.command.submit.v1 request: that operation accepts only authority-commit-operations.schema.json#/$defs/self_submit_request, including its closed ordinary_realm_bootstrap branch. The parent security transaction fixes the recovery unit type, slot count, order and authorization; this array alone grants no generic Event batch admission.
* events · array<$ref #/$defs/EventAdmissionSubmission>
items · object · $ref #/$defs/EventAdmissionSubmission
One exact producer-signed Event submitted to the current governance Station, plus the approval signatures required by a grant, Realm governance or List WIP policy for the Event action or for this registered submit operation. There are no RealmCommit, typed current result, offline-lease or proof-bundle sidecars. approval_signatures is the only sidecar and it is deliberately outside event: the Event bytes and event_id are finished before any approval is signed, so attaching them never changes the Event (zh/authz/constraint-schema.md section 9.2.5).
* event · object · $ref ./event-envelope.schema.json
Closed producer-signed Event. Shared persistent Events become final only when the current Realm governance Station issues a RealmCommit in the derived Realm, Circle, or Sidecar stream.
allOf · allOf[0] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[2] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[3] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[4] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[5] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[6] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[7] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[8] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[9] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[10] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[11] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[12] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[13] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[14] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[15] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[16] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[17] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[18] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[19] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[20] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[21] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[22] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[23] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[24] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[25] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[26] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[27] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[28] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[29] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[30] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[31] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[32] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[33] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[34] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[35] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[36] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[37] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[38] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[39] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[40] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[41] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[42] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[43] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[44] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[45] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[46] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[47] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[48] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[49] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[50] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[51] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[52] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[53] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[54] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[55] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[56] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[57] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[58] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[59] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[60] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[61] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[62] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[63] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[64] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[65] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[66] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[67] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[68] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[69] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[70] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[71] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[72] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[73] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[74] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[75] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[76] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[77] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[78] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[79] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[80] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[81] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[82] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[83] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[84] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[85] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[86] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[87] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[88] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[89] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[90] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[91] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[92] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[93] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[94] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[95] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[96] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[97] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[98] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[99] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[100] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[101] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[102] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[103] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[104] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[105] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[106] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[107] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[108] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[109] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[110] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[111] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[112] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[113] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[114] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[115] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[116] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[117] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[118] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[119] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[120] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[121] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[122] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[123] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[124] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[125] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[126] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[127] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[128] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[129] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[130] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[131] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[132] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[133] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[134] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[135] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[136] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[137] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[138] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[139] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[140] · …
recursion truncated at depth 8; see source schema for full shape
* event_id · …
recursion truncated at depth 8; see source schema for full shape
* kind · …
recursion truncated at depth 8; see source schema for full shape
realm_id · …
recursion truncated at depth 8; see source schema for full shape
* scope_ref · …
recursion truncated at depth 8; see source schema for full shape
* actor_id · …
recursion truncated at depth 8; see source schema for full shape
executed_by · …
recursion truncated at depth 8; see source schema for full shape
authorization_ref · …
recursion truncated at depth 8; see source schema for full shape
applet_id · …
recursion truncated at depth 8; see source schema for full shape
external_ref · …
recursion truncated at depth 8; see source schema for full shape
* created_at · …
recursion truncated at depth 8; see source schema for full shape
semantic_refs · …
recursion truncated at depth 8; see source schema for full shape
* payload · …
recursion truncated at depth 8; see source schema for full shape
* producer_proof · …
recursion truncated at depth 8; see source schema for full shape
approval_signatures · array<$ref ./approval-signature.schema.json>
One ak.schema.approval_signature.v1 object per approver. An event-target signature binds approval_target.event_id equal to event.event_id. An operation-target signature is allowed only when capability-action-registry.json resolves its action to this exact carrier operation and binds request_canonical_digest to the original typed request with approval_signatures omitted. Every ingress that wraps EventAdmissionSubmission -- ordinary self submit, batch submission, control transactions, facade hand-off -- reuses this one field and MUST NOT define its own DTO. The array is omitted when no approval layer demands evidence; it MUST NOT be present and empty. The governance Station persists the evidence, the verification basis, the nonce consumption and the binding to this submission inside the same atomic acceptance transaction, and the shared Realm Event store keeps the original Event bytes unchanged.
items · …
recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[28] · object · $ref #/$defs/GrantList
Atomic subject-visible snapshot of active effective grants. Each row carries its own exact current-result revision; state_digest authenticates the list as a whole and is never a per-grant CAS operand.
* grants · array<$ref #/$defs/EffectiveCapabilityGrantRow>
items · object · $ref #/$defs/EffectiveCapabilityGrantRow
One active effective capability grant and the exact revision of that same capability_grant current result, read atomically by the governing Station. This revision is the only valid authoring basis for a subject-signed ak.capability.relinquish Event; state_digest, evaluated_at, Event ids and locally folded history MUST NOT substitute for it.
* grant · object · $ref ./capability-grant.schema.json
allOf · allOf[0] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] · …
recursion truncated at depth 8; see source schema for full shape
* id · …
recursion truncated at depth 8; see source schema for full shape
* schema · …
recursion truncated at depth 8; see source schema for full shape
realm_id · …
recursion truncated at depth 8; see source schema for full shape
* issuer_id · …
recursion truncated at depth 8; see source schema for full shape
* subject · …
recursion truncated at depth 8; see source schema for full shape
* actions · …
recursion truncated at depth 8; see source schema for full shape
* resources · …
recursion truncated at depth 8; see source schema for full shape
constraints · …
recursion truncated at depth 8; see source schema for full shape
* issued_at · …
recursion truncated at depth 8; see source schema for full shape
* status · …
recursion truncated at depth 8; see source schema for full shape
updated_by · …
recursion truncated at depth 8; see source schema for full shape
updated_at · …
recursion truncated at depth 8; see source schema for full shape
revoked_by · …
recursion truncated at depth 8; see source schema for full shape
revoked_at · …
recursion truncated at depth 8; see source schema for full shape
* issuer_authority_refs · …
recursion truncated at depth 8; see source schema for full shape
* authority_depth · …
recursion truncated at depth 8; see source schema for full shape
* authority_root_refs · …
recursion truncated at depth 8; see source schema for full shape
(^x_[a-z][a-z0-9_]{0,63}$) · …
recursion truncated at depth 8; see source schema for full shape
* revision · object · $ref ./typed-current-result.schema.json#/$defs/revision
* commit_id · …
recursion truncated at depth 8; see source schema for full shape
* stream_position · …
recursion truncated at depth 8; see source schema for full shape
* state_digest · string
Digest of the complete effective-list snapshot. It MUST NOT be copied into expected_revision or otherwise treated as one grant's revision.
pattern: ^(sha256|blake3):[0-9a-f]{64}$
* evaluated_at · string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
anyOf · anyOf[29] · object · $ref #/$defs/IdentityDocumentView
Result of ak.root.identity.document.resource.get.v1 — current DID Document plus normalized view hints.
* did_document · object
Raw DID Core document with W3C field names preserved.
normalized_view · object
Optional Arkret normalized principal view (snake_case) — derived projection only, NOT a re-publishable DID Document. See zh/identity/identity-did.md §6.
method_evidence · oneOf[3] · $ref ./identity-resolution.schema.json#/$defs/method_history_evidence
Adapter-routed evidence. evidence_kind is the single-source discriminator: the receiver resolves it through did-method-adapter-registry.json method_evidence_kind, which is unique across active adapters, to exactly one active adapter for this versioned schema. The evidence carries no adapter_version; an adapter change requires a new schema/operation version rather than a registry drift under the same wire shape. Unknown evidence kinds fail closed.
oneOf · oneOf[0] · $ref #/$defs/webvh_method_history_evidence · $ref #/$defs/webvh_method_history_evidence
oneOf · oneOf[1] · $ref #/$defs/did_web_method_history_evidence · $ref #/$defs/did_web_method_history_evidence
oneOf · oneOf[2] · $ref #/$defs/did_key_method_history_evidence · $ref #/$defs/did_key_method_history_evidence
cached_at · string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
anyOf · anyOf[30] · object · $ref #/$defs/IdentityLogListOutcome
Result of ak.root.identity.log.read.list.v1. Entries are returned in the DID method's own native log form: for did:webvh each entry is a verbatim did.jsonl log entry with its native versionId, entryHash chain and Data Integrity proof. Arkret defines no parallel entry envelope, sequence numbering, hash chain or proof transcript over DID logs — the method already provides all of them, and a second signed representation of the same history could disagree with the first. Methods without a native history (did:web) MUST report that rather than being wrapped in a shape that implies one.
* did · string · $ref ./common-ids.schema.json#/$defs/did
Canonical bare DID used for registration, DID method resolution and owner-published current resolution. It contains no path, query or fragment and MUST project through the registered method adapter to exactly one did_core_id.
pattern: ^did:[a-z0-9]+:[^\s/?#]+$
* method · string
DID method of the returned log, e.g. did:webvh. Consumers dispatch parsing and verification on this value.
native_history · boolean
False when the method has no native key history at all (did:web). Such a response MUST return an empty entries array; the server MUST NOT synthesise entries, sequence numbers or a chain the method does not have.
* entries · array<object>
Verbatim method-native log entries in method order. Arkret does not reinterpret, renumber or re-sign them; verification follows the method specification.
items · object
next_cursor · string
Opaque continuation cursor for the next page when has_more=true.
* has_more · boolean
anyOf · anyOf[31] · object · $ref #/$defs/IdentityReceiptListOutcome
Result of ak.root.identity.receipts.read.list.v1. receipts[] is a tagged union over two distinct object families discriminated by their schema constant: ak.schema.identity_receipt.v1 records a role inside a DID registry consensus group (writer / witness / replica) and binds seq + accepted_entry_digest, while ak.schema.did_webvh_witness_receipt.v1 records a did:webvh method witness observed at a specific versionId. The two say different things with the same English word, so the discriminator is mandatory and a verifier MUST branch on it rather than infer intent from which optional fields happen to be present.
* receipts · array<oneOf[2]>
items · oneOf[2]
oneOf · oneOf[0] · object · $ref ./identity-receipt.schema.json
* schema · …
recursion truncated at depth 8; see source schema for full shape
* receipt_id · …
recursion truncated at depth 8; see source schema for full shape
* subject_did · …
recursion truncated at depth 8; see source schema for full shape
* seq · …
recursion truncated at depth 8; see source schema for full shape
* accepted_entry_digest · …
recursion truncated at depth 8; see source schema for full shape
* registry_id · …
recursion truncated at depth 8; see source schema for full shape
* witness_role · …
recursion truncated at depth 8; see source schema for full shape
audience · …
recursion truncated at depth 8; see source schema for full shape
* created_at · …
recursion truncated at depth 8; see source schema for full shape
* signature · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object · $ref ./did-webvh-witness-receipt.schema.json
Arkret-layer, cacheable and auditable record that a named did:webvh witness was observed attesting a specific log version. It is deliberately a separate object family from ak.schema.identity_receipt.v1: that one records a role (writer / witness / replica) inside a DID registry consensus group and binds seq + accepted_entry_digest, whereas this one binds a did:webvh method versionId and a witness did:key drawn from parameters.witness. Overloading one object with both meanings would leave half its required fields meaningless on either branch and force verifiers to guess which sense of the word witness applies. This receipt NEVER substitutes for method conformance: a verifier MUST still fetch and verify the standard did-witness.json proofs, the entry hash chain and the controller proof. See zh/identity/identity-did.md.
* schema · …
recursion truncated at depth 8; see source schema for full shape
* receipt_id · …
recursion truncated at depth 8; see source schema for full shape
* subject_did · …
recursion truncated at depth 8; see source schema for full shape
* version_id · …
recursion truncated at depth 8; see source schema for full shape
log_head_digest · …
recursion truncated at depth 8; see source schema for full shape
* witness_did · …
recursion truncated at depth 8; see source schema for full shape
* witness_verification_method · …
recursion truncated at depth 8; see source schema for full shape
* controlling_organization_did · …
recursion truncated at depth 8; see source schema for full shape
* observed_at · …
recursion truncated at depth 8; see source schema for full shape
source_url · …
recursion truncated at depth 8; see source schema for full shape
* issuer_id · …
recursion truncated at depth 8; see source schema for full shape
trust_domain · …
recursion truncated at depth 8; see source schema for full shape
audience · …
recursion truncated at depth 8; see source schema for full shape
* expires_at · …
recursion truncated at depth 8; see source schema for full shape
* created_at · …
recursion truncated at depth 8; see source schema for full shape
* signature · …
recursion truncated at depth 8; see source schema for full shape
threshold_met · boolean
True when the returned receipt set satisfies the effective witness threshold for the requested head. The effective threshold is the strictest intersection of the method-native parameters.witness.threshold and the deployment / Realm policy minimum (identity-did.md §3.4.2), and distinctness is counted over controlling_organization_did where policy requires distinct organizations. Omitted when the registry cannot evaluate threshold policy for this query; an omitted value MUST NOT be read as true. A true value is an Arkret-layer convenience and MUST NOT replace verifying the standard did-witness.json proofs.
anyOf · anyOf[32] · object · $ref #/$defs/IdentityResolveOutcome
did_document · object
key_log_head · string · $ref ./account-operations.schema.json#/$defs/digest
pattern: ^(sha256|blake3):[0-9a-f]{64}$
seq · integer
method_evidence · oneOf[1] · $ref #/$defs/IdentityMethodEvidence
oneOf · oneOf[0] · object · $ref #/$defs/DidWebvhIdentityMethodEvidence
Method-native pins derived only after fail-closed verification of the complete did:webvh history. control_key_digest is SHA-256 over the decoded canonical multikey bytes of parameters.updateKeys[0] at version_id.
* kind · const "did_webvh"
enum: "did_webvh"
* version_id · string
pattern: ^(?!ak:)
* control_key_digest · string
pattern: ^sha256:[0-9a-f]{64}$
receipts · array<$ref ./identity-receipt.schema.json>
items · object · $ref ./identity-receipt.schema.json
* schema · const "ak.schema.identity_receipt.v1"
Canonical schema discriminator. Aligned with schema-registry.json; lets validators distinguish identity registry receipts from other receipt envelopes (e.g. audit-ryw-receipt, event-batch-receipt).
enum: "ak.schema.identity_receipt.v1"
* receipt_id · string
pattern: ^ak:receipt:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$
* subject_did · string · $ref ./common-ids.schema.json#/$defs/did
Canonical bare DID used for registration, DID method resolution and owner-published current resolution. It contains no path, query or fragment and MUST project through the registered method adapter to exactly one did_core_id.
pattern: ^did:[a-z0-9]+:[^\s/?#]+$
* seq · integer
* accepted_entry_digest · string
SHA-256 of RFC 8785 JCS of the exact complete accepted method-native log entry, including its control proofs. It commits to immutable accepted bytes at subject_did and seq, not a PCR Event or an unsigned-operation projection. Receipts with different digests at the same position MUST NOT contribute to the same consensus quorum.
pattern: ^sha256:[0-9a-f]{64}$
* registry_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* witness_role · string (enum)
Issuer's role in the DID registry consensus group. Required so verifiers can apply role-specific freshness / quorum rules; an absent role would force the verifier to guess writer vs replica semantics.
enum: "writer" "witness" "replica"
audience · string
Optional audience binding (verifier DID, service DID, or domain). When present, verifiers MUST reject the receipt outside that audience context to prevent cross-protocol reuse.
* created_at · $ref #/$defs/timestamp · $ref #/$defs/timestamp
* signature · object · $ref ./event-envelope.schema.json#/$defs/proof
Generic detached-JWS proof shape reused by non-Event schemas (snapshot signature, snapshot witness attestations, identity receipts, handle claims, etc.). MUST NOT be used as the shape of Event Envelope `producer_proof` — Event proofs reference $defs/event_proof and bind canonical Event bytes via `event_digest`. Non-Event signed objects MUST define an object-family signing-context constant and include it in the canonical proof binding object with payload_digest; the context constant is not a wire field in this generic shape. drift detection: `payload_digest#event_proof` in forbidden-wire-fields.json is the hard-reject mirror of this rule. New non-Event signed objects MAY $ref this shape; new signed Event-shaped objects MUST instead $ref event_proof.
* kind · …
recursion truncated at depth 8; see source schema for full shape
* verification_method · …
recursion truncated at depth 8; see source schema for full shape
* payload_digest · …
recursion truncated at depth 8; see source schema for full shape
* created_at · …
recursion truncated at depth 8; see source schema for full shape
domain · …
recursion truncated at depth 8; see source schema for full shape
audience · …
recursion truncated at depth 8; see source schema for full shape
proof_purpose · …
recursion truncated at depth 8; see source schema for full shape
* jws · …
recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[33] · object · $ref #/$defs/IdentityResolveRequestBody
* did · string · $ref ./common-ids.schema.json#/$defs/did
Canonical bare DID used for registration, DID method resolution and owner-published current resolution. It contains no path, query or fragment and MUST project through the registered method adapter to exactly one did_core_id.
pattern: ^did:[a-z0-9]+:[^\s/?#]+$
requested_evidence_kinds · array<string (enum)>
items · string (enum)
enum: "did_webvh"
anyOf · anyOf[34] · object · $ref #/$defs/InitialSessionGrantIntent
Initial Standard SessionGrant intent embedded in identity_creation registration. It reuses the DPoP holder key established by account handoff; Account Authority recomputes RFC 7638 thumbprint of session_public_key and requires equality with the handoff/control-proof dpop_jkt. It is not a separate authorization or credential.
* device_id · string · $ref ./common-ids.schema.json#/$defs/device_id
pattern: ^ak:device:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$
* session_public_key · string (canonical-public-jwk-jcs) · format=canonical-public-jwk-jcs
Exact RFC 8785 JCS public JWK for the existing handoff DPoP holder key. Private members are forbidden.
* audience_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
anyOf · anyOf[35] · object · $ref #/$defs/MlsGroupStateMaterialOutcome
Exact RFC 9420 public group-state material. *_bytes_b64 use unpadded base64url. Consumers MUST decode each content-addressed Blob ref's embedded suite, hash the raw bytes under that suite, compare the digest, verify GroupInfo and ratchet_tree consistency, then derive leaf_index only from occupied leaves in the verified tree. Blob suites are independent of the fixed SHA-256 Event/RealmCommit identity suite.
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* effective_scope · oneOf[3] · $ref ./event-payload.schema.json#/$defs/effective_scope
oneOf · oneOf[0] · object
* kind · const "realm"
enum: "realm"
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
oneOf · oneOf[1] · object
* kind · const "circle"
enum: "circle"
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* circle_id · string · $ref ./common-ids.schema.json#/$defs/circle_id
pattern: ^ak:circle:[A-Za-z0-9_-]{44}$
oneOf · oneOf[2] · object
* kind · const "sidecar"
enum: "sidecar"
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* sidecar_id · string · $ref ./common-ids.schema.json#/$defs/sidecar_id
pattern: ^ak:sidecar:[A-Za-z0-9_-]{44}$
* mls_group_id · string · $ref ./common-ids.schema.json#/$defs/mls_group_id
RFC 9420 group_id as base64url_no_pad(SHA-256(UTF8("ak.mls.group_id.v1") || 0x00 || canonical_effective_scope_key_bytes(effective_scope))), so exactly 43 characters. Derived by the reducer and the SDK from the effective scope alone; actors never submit it. The v1 formula is the only one: the earlier reversible base64url of the scope key bytes MUST NOT be accepted alongside it. See zh/models/realm-and-space.md section 2.2.
pattern: ^[A-Za-z0-9_-]{43}$
* epoch · const 0
enum: 0
* group_state_event_id · string · $ref #/$defs/EventId
pattern: ^ak:event:[A-Za-z0-9_-]{44}$
* group_info_ref · string
Copied byte-for-byte from the accepted ak.mls.genesis payload; the embedded Blob digest suite is the sole wire carrier of the material digest and is independent of the fixed SHA-256 Event/RealmCommit identity suite (encoding.md 4.0.1).
pattern: ^ak:blob:(?:sha256|blake3):[0-9a-f]{64}$
* group_info_bytes_b64 · string
pattern: ^[A-Za-z0-9_-]+$
* ratchet_tree_ref · string
Copied byte-for-byte from the accepted ak.mls.genesis payload; the embedded Blob digest suite is the sole wire carrier of the material digest and is independent of the fixed SHA-256 Event/RealmCommit identity suite (encoding.md 4.0.1).
pattern: ^ak:blob:(?:sha256|blake3):[0-9a-f]{64}$
* ratchet_tree_bytes_b64 · string
pattern: ^[A-Za-z0-9_-]+$
anyOf · anyOf[36] · object · $ref #/$defs/MlsGroupStateMaterialRequestBody
Read-only service request for the exact public MLS epoch-0 GroupInfo and ratchet_tree bytes committed by one accepted ak.mls.genesis Event. Every Genesis selector is copied from that Event. When caller_actor_id is present, target_commit_event_ref and target_epoch are mandatory; governance checks current and target-cut member/history authority and source Station replication right at the target accepted Commit cut. Without caller_actor_id this remains the original Station replication-only read, with source Station replication right checked at the Genesis Commit position.
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* effective_scope · oneOf[3] · $ref ./event-payload.schema.json#/$defs/effective_scope
oneOf · oneOf[0] · object
* kind · const "realm"
enum: "realm"
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
oneOf · oneOf[1] · object
* kind · const "circle"
enum: "circle"
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* circle_id · string · $ref ./common-ids.schema.json#/$defs/circle_id
pattern: ^ak:circle:[A-Za-z0-9_-]{44}$
oneOf · oneOf[2] · object
* kind · const "sidecar"
enum: "sidecar"
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* sidecar_id · string · $ref ./common-ids.schema.json#/$defs/sidecar_id
pattern: ^ak:sidecar:[A-Za-z0-9_-]{44}$
* mls_group_id · string · $ref ./common-ids.schema.json#/$defs/mls_group_id
RFC 9420 group_id as base64url_no_pad(SHA-256(UTF8("ak.mls.group_id.v1") || 0x00 || canonical_effective_scope_key_bytes(effective_scope))), so exactly 43 characters. Derived by the reducer and the SDK from the effective scope alone; actors never submit it. The v1 formula is the only one: the earlier reversible base64url of the scope key bytes MUST NOT be accepted alongside it. See zh/models/realm-and-space.md section 2.2.
pattern: ^[A-Za-z0-9_-]{43}$
* epoch · const 0
enum: 0
* group_state_event_id · string · $ref #/$defs/EventId
pattern: ^ak:event:[A-Za-z0-9_-]{44}$
caller_actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind · const "account"
enum: "account"
* account_id · $ref #/$defs/account_id · $ref #/$defs/account_id
oneOf · oneOf[1] · object
* kind · const "service"
enum: "service"
* service_id · $ref #/$defs/did_core_id · $ref #/$defs/did_core_id
target_commit_event_ref · string · $ref #/$defs/EventId
pattern: ^ak:event:[A-Za-z0-9_-]{44}$
target_epoch · integer
* group_info_ref · string
Copied byte-for-byte from the accepted ak.mls.genesis payload; the embedded Blob digest suite is the sole wire carrier of the material digest and is independent of the fixed SHA-256 Event/RealmCommit identity suite (encoding.md 4.0.1).
pattern: ^ak:blob:(?:sha256|blake3):[0-9a-f]{64}$
* ratchet_tree_ref · string
Copied byte-for-byte from the accepted ak.mls.genesis payload; the embedded Blob digest suite is the sole wire carrier of the material digest and is independent of the fixed SHA-256 Event/RealmCommit identity suite (encoding.md 4.0.1).
pattern: ^ak:blob:(?:sha256|blake3):[0-9a-f]{64}$
max_response_bytes · integer
example: 8388608
anyOf · anyOf[37] · object · $ref #/$defs/ModerationReportOutcome
* report_id · string
pattern: ^ak:report:[A-Za-z0-9_-]{44}$
routed_to_ids · array<$ref ./common-ids.schema.json#/$defs/did_core_id>
Stable core_ids selected as moderation routing destinations. MUST be omitted for an ordinary reporter and MAY be serialized only when the caller independently holds moderation/governance capability for the report's exact scope. Endpoint discovery and DID verification remain separate resolution steps.
items · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
anyOf · anyOf[38] · object · $ref #/$defs/OrganizationRegistrationChallenge
Single-use control challenge. Every binding field exists to close one replay path: purpose separates this proof from any other signature the organization makes, audience and trust_domain pin it to this deployment, origin pins the HTTP surface, nonce makes it unrepeatable, and the expiry window bounds how long a captured proof stays useful. A registry MUST consume the challenge on the first successful use and atomically persist (challenge_id, canonical_request_digest, outcome). Only a byte-identical retry may return that stored outcome; the same challenge with any different digest is invalid.
* challenge_id · string
pattern: ^ak:organization_registration_challenge:[0-9a-f]{64}$
* organization_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* organization_did · string · $ref ./common-ids.schema.json#/$defs/did
Canonical bare DID used for registration, DID method resolution and owner-published current resolution. It contains no path, query or fragment and MUST project through the registered method adapter to exactly one did_core_id.
pattern: ^did:[a-z0-9]+:[^\s/?#]+$
* purpose · const "ak.organization_registration_control_proof.v1"
Fixed purpose tag, identical to the signing context of OrganizationControlProof.proofs[]. A proof produced for any other purpose MUST NOT verify here.
enum: "ak.organization_registration_control_proof.v1"
* nonce · string
pattern: ^[A-Za-z0-9_-]{22,128}$
* audience_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* origin · string (uri) · format=uri · $ref ./common-ids.schema.json#/$defs/web_origin
Canonical HTTP(S) Web Origin: lowercase scheme/host plus an optional valid non-default effective port. Userinfo, path (including a trailing slash), query, fragment, explicit :80 on HTTP, and explicit :443 on HTTPS are forbidden.
pattern: ^(?:http://(?:\[[0-9A-Fa-f:.]+\]|[a-z0-9](?:[a-z0-9.-]*[a-z0-9])?)(?::(?!80$)(?:[1-9]|[1-9][0-9]{1,3}|[1-5][0-9]{4}|6[0-4][0-9]{3}|65[0-4][0-9]{2}|655[0-2][0-9]|6553[0-5]))?|https://(?:\[[0-9A-Fa-f:.]+\]|[a-z0-9](?:[a-z0-9.-]*[a-z0-9])?)(?::(?!443$)(?:[1-9]|[1-9][0-9]{1,3}|[1-5][0-9]{4}|6[0-4][0-9]{3}|65[0-4][0-9]{2}|655[0-2][0-9]|6553[0-5]))?)$
* trust_domain · string · $ref ./common-ids.schema.json#/$defs/trust_domain
pattern: ^ak:trust_domain:[a-z0-9][a-z0-9._\-:]{0,127}$
* local_admin_subject_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* requested_scopes · array<$ref #/$defs/OrganizationRegistrationScope>
items · string (enum) · $ref #/$defs/OrganizationRegistrationScope
Closed set of local administrative scopes a registration may delegate. organization_profile_manage covers this deployment's local organization profile and display; organization_realm_endorse permits issuing ak.realm.organization statements on the organization's behalf; organization_service_delegate permits declaring organization-to-service delegations locally. The set is closed because an open scope vocabulary would let a deployment mint authority the organization never consented to. Holding a scope is a permission to act later, not an action: registration by itself creates no Realm, membership, governance-Station authority, capability or service delegation.
enum: "organization_profile_manage" "organization_realm_endorse" "organization_service_delegate"
* expires_at · string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
* created_at · string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
anyOf · anyOf[39] · object · $ref #/$defs/OrganizationRegistrationChallengeRequestBody
Request a single-use control challenge for an external Organization DID. Two phases are mandatory: the registry issues the challenge and remembers it, then the caller proves control against it. Folding this into ensure would let the caller supply its own challenge, at which point neither freshness nor single use can be established by the receiver.
* organization_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* organization_did · string · $ref ./common-ids.schema.json#/$defs/did
Canonical bare DID used for registration, DID method resolution and owner-published current resolution. It contains no path, query or fragment and MUST project through the registered method adapter to exactly one did_core_id.
pattern: ^did:[a-z0-9]+:[^\s/?#]+$
* local_admin_subject_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* requested_scopes · array<$ref #/$defs/OrganizationRegistrationScope>
items · string (enum) · $ref #/$defs/OrganizationRegistrationScope
Closed set of local administrative scopes a registration may delegate. organization_profile_manage covers this deployment's local organization profile and display; organization_realm_endorse permits issuing ak.realm.organization statements on the organization's behalf; organization_service_delegate permits declaring organization-to-service delegations locally. The set is closed because an open scope vocabulary would let a deployment mint authority the organization never consented to. Holding a scope is a permission to act later, not an action: registration by itself creates no Realm, membership, governance-Station authority, capability or service delegation.
enum: "organization_profile_manage" "organization_realm_endorse" "organization_service_delegate"
anyOf · anyOf[40] · object · $ref #/$defs/OrganizationRegistrationEnsureRequestBody
Register an external Organization identity with this deployment by submitting both its stable organization_id core and current published organization_did. Idempotent on organization_id: replaying the same registration returns the existing binding with created=false. This operation registers a reference and a local administrative binding; it does not host the DID's method history, does not make this deployment its controller, and does not create Realm state.
* organization_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* organization_did · string · $ref ./common-ids.schema.json#/$defs/did
Canonical bare DID used for registration, DID method resolution and owner-published current resolution. It contains no path, query or fragment and MUST project through the registered method adapter to exactly one did_core_id.
pattern: ^did:[a-z0-9]+:[^\s/?#]+$
* challenge_id · string
pattern: ^ak:organization_registration_challenge:[0-9a-f]{64}$
* version_id · string
The exact resolved DID version the control proof was made against. Pinning the version is what makes the receipt auditable later: without it, a receipt asserts control at an unknown point in the DID's history.
pattern: ^(?!ak:)
* log_head_digest · string
pattern: ^sha256:[0-9a-f]{64}$
* control_proof · object · $ref #/$defs/OrganizationControlProof
Method-native proof that the caller controls the external Organization DID at the pinned version. proof_kind is a closed discriminator with exactly two members, both of which describe a MATURE, already-published DID. Creating a new Organization DID is a separate inception / governance ceremony and deliberately has no member here: a receiver must never have to guess whether a proof asserts control of existing state or creation of new state. This object never carries an Arkret-issued challenge signature in place of method-native control evidence.
allOf · allOf[0] · ?
* proof_kind · string (enum)
resolved_verification_method: a single signature by a verification method that is in the organization DID's control relationship at version_id. governance_quorum: a threshold of signatures from the organization's governance key set. Witness attestation is neither of these and MUST NOT be substituted for control evidence (identity-did.md §8.1).
enum: "resolved_verification_method" "governance_quorum"
quorum_threshold · integer
Required when proof_kind=governance_quorum and forbidden otherwise. The number of distinct valid governance signatures the organization's own policy demands. proofs[] MUST contain at least this many entries signed by distinct verification methods; JSON Schema cannot compare the two, so the receiver MUST enforce it and fail closed when short.
* proofs · array<$ref ./event-envelope.schema.json#/$defs/proof>
Detached proofs over canonical_json({context:'ak.organization_registration_control_proof.v1', challenge_id, organization_id, organization_did, local_admin_subject, version_id, log_head_digest, verification_method, created_at}). The verifier independently validates the published organization_did and requires project(organization_did)=organization_id before checking the DID URL verification_method. Binding the challenge, stable core, DID, beneficiary admin and exact version together prevents replay across deployments, resolutions or beneficiaries.
items · object · $ref ./event-envelope.schema.json#/$defs/proof
Generic detached-JWS proof shape reused by non-Event schemas (snapshot signature, snapshot witness attestations, identity receipts, handle claims, etc.). MUST NOT be used as the shape of Event Envelope `producer_proof` — Event proofs reference $defs/event_proof and bind canonical Event bytes via `event_digest`. Non-Event signed objects MUST define an object-family signing-context constant and include it in the canonical proof binding object with payload_digest; the context constant is not a wire field in this generic shape. drift detection: `payload_digest#event_proof` in forbidden-wire-fields.json is the hard-reject mirror of this rule. New non-Event signed objects MAY $ref this shape; new signed Event-shaped objects MUST instead $ref event_proof.
* kind · …
recursion truncated at depth 8; see source schema for full shape
* verification_method · …
recursion truncated at depth 8; see source schema for full shape
* payload_digest · …
recursion truncated at depth 8; see source schema for full shape
* created_at · …
recursion truncated at depth 8; see source schema for full shape
domain · …
recursion truncated at depth 8; see source schema for full shape
audience · …
recursion truncated at depth 8; see source schema for full shape
proof_purpose · …
recursion truncated at depth 8; see source schema for full shape
* jws · …
recursion truncated at depth 8; see source schema for full shape
* local_admin_subject_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* requested_scopes · array<$ref #/$defs/OrganizationRegistrationScope>
MUST be identical to the set carried by the referenced challenge; a mismatch means the proof was made for different authority than is being claimed.
items · string (enum) · $ref #/$defs/OrganizationRegistrationScope
Closed set of local administrative scopes a registration may delegate. organization_profile_manage covers this deployment's local organization profile and display; organization_realm_endorse permits issuing ak.realm.organization statements on the organization's behalf; organization_service_delegate permits declaring organization-to-service delegations locally. The set is closed because an open scope vocabulary would let a deployment mint authority the organization never consented to. Holding a scope is a permission to act later, not an action: registration by itself creates no Realm, membership, governance-Station authority, capability or service delegation.
enum: "organization_profile_manage" "organization_realm_endorse" "organization_service_delegate"
handle_attestation · object
Optional supporting attestation only. An organization handle or domain claim may improve discovery and display, but MUST NOT substitute for DID control or quorum proof: whoever operates a domain is not thereby the controller of the organization's DID. Named attestation rather than evidence because it carries exactly one material family (common-fields.md R6).
* subject_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* handle · string
* issuer_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* audience · string
* status · string (enum)
The issuer's assertion at signing time. It is a floor, not a guarantee: a receiver MUST still consult the issuer's current revocation state before relying on the handle for display, because a self-asserted active is exactly what a revoked attestation would also carry.
enum: "active" "revoked"
* expires_at · string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
anyOf · anyOf[41] · object · $ref #/$defs/OrganizationRegistrationOutcome
Result of every organization registration command and of the read surface. Identity, DID, generation and version are read from the signed registration_receipt. created is true exactly on a call that opened a new generation.
* registration_receipt · object · $ref #/$defs/OrganizationRegistrationReceipt
Provider-signed record that this deployment accepted an external Organization DID binding. receipt_claims is exactly the object formed by removing registration_receipt_id and proof from the receipt; registration_receipt_id is ak:organization_registration_receipt:<lowercase hex SHA-256(canonical_json(receipt_claims))>. proof.payload_digest hashes the complete receipt after registration_receipt_id is inserted and proof is removed, so neither digest is self-referential. proof is a detached JWS over the ak.organization_registration_receipt_proof.v1 binding object. The receipt proves acceptance of one generation of one local binding and nothing else: it is not a Realm capability, not membership, not a governance-Station designation, and not a service delegation.
* registration_receipt_id · string
ak:organization_registration_receipt: plus lowercase hex SHA-256(canonical_json(receipt with registration_receipt_id and proof both omitted)).
pattern: ^ak:organization_registration_receipt:[0-9a-f]{64}$
* organization_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* organization_did · string · $ref ./common-ids.schema.json#/$defs/did
Canonical bare DID used for registration, DID method resolution and owner-published current resolution. It contains no path, query or fragment and MUST project through the registered method adapter to exactly one did_core_id.
pattern: ^did:[a-z0-9]+:[^\s/?#]+$
* registration_generation · integer
Monotonic generation of the binding for this stable organization did_core_id, starting at 1. A same-core did refresh does not create a different organization identity; terminal registration states remain per generation.
* version_id · string
pattern: ^(?!ak:)
* log_head_digest · string
pattern: ^sha256:[0-9a-f]{64}$
* control_proof_kind · string (enum)
Mirrors OrganizationControlProof.proof_kind so a later auditor can tell which commitment control_key_digest is over without re-fetching the original request.
enum: "resolved_verification_method" "governance_quorum"
* control_key_digest · string
Under resolved_verification_method, the digest of the active control/update public key at version_id. Under governance_quorum, the digest of the canonical governance key set head that satisfied the threshold. It is never a next-key commitment and never private material.
pattern: ^sha256:[0-9a-f]{64}$
* local_admin_subject_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* delegated_scopes · array<$ref #/$defs/OrganizationRegistrationScope>
items · string (enum) · $ref #/$defs/OrganizationRegistrationScope
Closed set of local administrative scopes a registration may delegate. organization_profile_manage covers this deployment's local organization profile and display; organization_realm_endorse permits issuing ak.realm.organization statements on the organization's behalf; organization_service_delegate permits declaring organization-to-service delegations locally. The set is closed because an open scope vocabulary would let a deployment mint authority the organization never consented to. Holding a scope is a permission to act later, not an action: registration by itself creates no Realm, membership, governance-Station authority, capability or service delegation.
enum: "organization_profile_manage" "organization_realm_endorse" "organization_service_delegate"
* status · string (enum)
Closed lifecycle. active: control evidence is current. stale: the pinned version no longer reflects current control (controller rotation) or the evidence has aged out; low-risk reads may continue but high-risk paths MUST fail closed until a successful refresh. revoked: terminal for this generation, whether withdrawn locally, atomically superseded by a new generation, or forced by deactivation of the external DID. A signed historical receipt can retain status=active as an immutable audit artifact, but it authorizes only while its generation is the registry current generation and that registry state is active.
enum: "active" "stale" "revoked"
* issued_at · string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
* expires_at · string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
* issuer_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* proof · object · $ref ./event-envelope.schema.json#/$defs/proof
Generic detached-JWS proof shape reused by non-Event schemas (snapshot signature, snapshot witness attestations, identity receipts, handle claims, etc.). MUST NOT be used as the shape of Event Envelope `producer_proof` — Event proofs reference $defs/event_proof and bind canonical Event bytes via `event_digest`. Non-Event signed objects MUST define an object-family signing-context constant and include it in the canonical proof binding object with payload_digest; the context constant is not a wire field in this generic shape. drift detection: `payload_digest#event_proof` in forbidden-wire-fields.json is the hard-reject mirror of this rule. New non-Event signed objects MAY $ref this shape; new signed Event-shaped objects MUST instead $ref event_proof.
* kind · string (enum)
Generic detached JWS proof over a canonical non-Event payload binding object that includes an object-family context constant.
enum: "detached_jws"
* verification_method · string
DID URL of the signing key for this non-Event detached proof. Same pattern as $defs/event_proof.verification_method; semantics are decoupled from Event proof (see $defs/event_proof for the Event-only shape).
pattern: ^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$
* payload_digest · $ref #/$defs/digest · $ref #/$defs/digest
Generic non-Event detached-proof hash. This $defs/proof shape is reused by non-Event schemas; Event.properties.producer_proof references $defs/event_proof and MUST use event_digest instead.
* created_at · $ref #/$defs/timestamp · $ref #/$defs/timestamp
domain · string
audience · oneOf[2]
oneOf · oneOf[0] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · …
recursion truncated at depth 8; see source schema for full shape
proof_purpose · string (enum)
Optional role discriminator for non-Event proofs. HandleClaim core, status and revocation carriers make issuer_attestation, holder_acceptance, status_attestation and revocation_authorization load-bearing. governance_authorization marks a resource-governance-key authorization (directory withdraw/takedown-appeal, discovery-directory.md 8.7.1). Generic proof consumers ignore it unless their object-family contract makes it load-bearing.
enum: "issuer_attestation" "holder_acceptance" "status_attestation" "revocation_authorization" "governance_authorization"
* jws · string
pattern: ^[A-Za-z0-9_-]+\.\.[A-Za-z0-9_-]+$
* created · boolean
True exactly when this call opened a new generation: the first registration, a re-registration after revoke, or an ensure that changed local_admin_subject or the scope set. False for a byte-identical ensure retry that matches the consumed challenge's canonical_request_digest and stored outcome, and for every read, refresh and revoke. Reusing the challenge with a different digest is an error, not created=false.
anyOf · anyOf[42] · object · $ref #/$defs/OrganizationRegistrationRefreshRequestBody
Re-prove control at a newer resolved version and re-issue the receipt. Scopes are not re-negotiated here; a scope change is a new ensure. Refresh exists because a binding pinned to one version stops proving current control the moment the organization rotates its controller.
* organization_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* organization_did · string · $ref ./common-ids.schema.json#/$defs/did
Canonical bare DID used for registration, DID method resolution and owner-published current resolution. It contains no path, query or fragment and MUST project through the registered method adapter to exactly one did_core_id.
pattern: ^did:[a-z0-9]+:[^\s/?#]+$
* challenge_id · string
pattern: ^ak:organization_registration_challenge:[0-9a-f]{64}$
* version_id · string
pattern: ^(?!ak:)
* log_head_digest · string
pattern: ^sha256:[0-9a-f]{64}$
* control_proof · object · $ref #/$defs/OrganizationControlProof
Method-native proof that the caller controls the external Organization DID at the pinned version. proof_kind is a closed discriminator with exactly two members, both of which describe a MATURE, already-published DID. Creating a new Organization DID is a separate inception / governance ceremony and deliberately has no member here: a receiver must never have to guess whether a proof asserts control of existing state or creation of new state. This object never carries an Arkret-issued challenge signature in place of method-native control evidence.
allOf · allOf[0] · ?
* proof_kind · string (enum)
resolved_verification_method: a single signature by a verification method that is in the organization DID's control relationship at version_id. governance_quorum: a threshold of signatures from the organization's governance key set. Witness attestation is neither of these and MUST NOT be substituted for control evidence (identity-did.md §8.1).
enum: "resolved_verification_method" "governance_quorum"
quorum_threshold · integer
Required when proof_kind=governance_quorum and forbidden otherwise. The number of distinct valid governance signatures the organization's own policy demands. proofs[] MUST contain at least this many entries signed by distinct verification methods; JSON Schema cannot compare the two, so the receiver MUST enforce it and fail closed when short.
* proofs · array<$ref ./event-envelope.schema.json#/$defs/proof>
Detached proofs over canonical_json({context:'ak.organization_registration_control_proof.v1', challenge_id, organization_id, organization_did, local_admin_subject, version_id, log_head_digest, verification_method, created_at}). The verifier independently validates the published organization_did and requires project(organization_did)=organization_id before checking the DID URL verification_method. Binding the challenge, stable core, DID, beneficiary admin and exact version together prevents replay across deployments, resolutions or beneficiaries.
items · object · $ref ./event-envelope.schema.json#/$defs/proof
Generic detached-JWS proof shape reused by non-Event schemas (snapshot signature, snapshot witness attestations, identity receipts, handle claims, etc.). MUST NOT be used as the shape of Event Envelope `producer_proof` — Event proofs reference $defs/event_proof and bind canonical Event bytes via `event_digest`. Non-Event signed objects MUST define an object-family signing-context constant and include it in the canonical proof binding object with payload_digest; the context constant is not a wire field in this generic shape. drift detection: `payload_digest#event_proof` in forbidden-wire-fields.json is the hard-reject mirror of this rule. New non-Event signed objects MAY $ref this shape; new signed Event-shaped objects MUST instead $ref event_proof.
* kind · …
recursion truncated at depth 8; see source schema for full shape
* verification_method · …
recursion truncated at depth 8; see source schema for full shape
* payload_digest · …
recursion truncated at depth 8; see source schema for full shape
* created_at · …
recursion truncated at depth 8; see source schema for full shape
domain · …
recursion truncated at depth 8; see source schema for full shape
audience · …
recursion truncated at depth 8; see source schema for full shape
proof_purpose · …
recursion truncated at depth 8; see source schema for full shape
* jws · …
recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[43] · object · $ref #/$defs/OrganizationRegistrationRevokeRequestBody
Withdraw the local binding. This is a local act with local effect only: it does not modify, deactivate or annotate the external DID's method history, which this deployment does not control.
* organization_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
reason_code · string (enum)
Closed reason set. superseded: replaced by a new binding for the same organization. withdrawn: the deployment or the organization ended the relationship.
enum: "organization_registration_superseded" "organization_registration_withdrawn"
anyOf · anyOf[44] · object · $ref #/$defs/ProjectionMorphList
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* morphs · array<$ref #/$defs/ProjectionMorphRow>
items · object · $ref #/$defs/ProjectionMorphRow
allOf · allOf[0] · ?
* morph_id · string
pattern: ^ak:morph:[A-Za-z0-9_-]{44}$
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* morph_kind · string
title · oneOf[2]
oneOf · oneOf[0] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · …
recursion truncated at depth 8; see source schema for full shape
* state · string (enum)
enum: "active" "archived" "redacted"
state_changed_at · oneOf[2] · $ref ./time.schema.json#/$defs/nullable_timestamp
oneOf · oneOf[0] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · …
recursion truncated at depth 8; see source schema for full shape
stage · oneOf[2]
Business-progression stage from the domain current result; null or absent when the object has never been written by ak.<kind>.stage.set. Orthogonal to the physical lifecycle in state (common-fields.md 5.3).
oneOf · oneOf[0] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · …
recursion truncated at depth 8; see source schema for full shape
stage_changed_at · oneOf[2] · $ref ./time.schema.json#/$defs/nullable_timestamp
Reducer-derived timestamp of the most recent stage transition; MUST NOT be present without stage (common-fields.md 5.3.1).
oneOf · oneOf[0] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · …
recursion truncated at depth 8; see source schema for full shape
created_by · oneOf[2]
oneOf · oneOf[0] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · …
recursion truncated at depth 8; see source schema for full shape
created_at · oneOf[2] · $ref ./time.schema.json#/$defs/nullable_timestamp
oneOf · oneOf[0] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · …
recursion truncated at depth 8; see source schema for full shape
updated_at · oneOf[2] · $ref ./time.schema.json#/$defs/nullable_timestamp
oneOf · oneOf[0] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · …
recursion truncated at depth 8; see source schema for full shape
* total · integer
next_cursor · string
pattern: ^ak:cursor:[A-Za-z0-9_-]+$
* has_more · boolean
anyOf · anyOf[45] · object · $ref #/$defs/ProjectionSpaceList
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* spaces · array<$ref #/$defs/ProjectionSpaceRow>
items · object · $ref #/$defs/ProjectionSpaceRow
oneOf · oneOf[0] · ?
oneOf · oneOf[1] · ?
* space_id · string
pattern: ^ak:space:[A-Za-z0-9_-]{44}$
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* kind · string
Space kind such as `board`, `list`, `folder`, or a profile-registered kind.
title · string (arkret-single-line-display-text) · format=arkret-single-line-display-text · $ref string-profiles.schema.json#/$defs/display_text_256
NFC multilingual single-line display text; mixed scripts, emoji, and symbols are allowed.
pattern: ^[^\u0000-\u001F\u007F-\u009F\u202A-\u202E\u2066-\u2069\uFEFF]*[^\s\u0000-\u001F\u007F-\u009F\u202A-\u202E\u2066-\u2069\uFEFF][^\u0000-\u001F\u007F-\u009F\u202A-\u202E\u2066-\u2069\uFEFF]*$
encrypted_metadata · object · $ref ./encrypted-envelope.schema.json
Minimal ciphertext wire. purpose, effective scope and Event kind come from the frozen signed outer Event; mls_group_id is derived from that scope. The canonical pre-encryption header is reconstructed and is not duplicated on wire.
* version · …
recursion truncated at depth 8; see source schema for full shape
* content_type · …
recursion truncated at depth 8; see source schema for full shape
* encryption_context · …
recursion truncated at depth 8; see source schema for full shape
* ciphertext · …
recursion truncated at depth 8; see source schema for full shape
parent_space_id · string | null
rank · string | null
* state · string (enum)
enum: "active" "archived" "tombstoned"
state_changed_at · oneOf[2] · $ref ./time.schema.json#/$defs/nullable_timestamp
oneOf · oneOf[0] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · …
recursion truncated at depth 8; see source schema for full shape
created_by · oneOf[2]
oneOf · oneOf[0] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · …
recursion truncated at depth 8; see source schema for full shape
created_at · oneOf[2] · $ref ./time.schema.json#/$defs/nullable_timestamp
oneOf · oneOf[0] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · …
recursion truncated at depth 8; see source schema for full shape
updated_at · oneOf[2] · $ref ./time.schema.json#/$defs/nullable_timestamp
oneOf · oneOf[0] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · …
recursion truncated at depth 8; see source schema for full shape
* total · integer
next_cursor · string
pattern: ^ak:cursor:[A-Za-z0-9_-]+$
* has_more · boolean
anyOf · anyOf[46] · object · $ref #/$defs/ProjectionStrandList
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* strands · array<$ref #/$defs/ProjectionStrandRow>
items · object · $ref #/$defs/ProjectionStrandRow
allOf · allOf[0] · ?
* strand_id · string
pattern: ^ak:strand:[A-Za-z0-9_-]{44}$
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* state · string (enum)
enum: "active" "archived" "redacted"
state_changed_at · oneOf[2] · $ref ./time.schema.json#/$defs/nullable_timestamp
oneOf · oneOf[0] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · …
recursion truncated at depth 8; see source schema for full shape
stage · oneOf[2]
Business-progression stage from the domain current result; null or absent when the object has never been written by ak.<kind>.stage.set. Orthogonal to the physical lifecycle in state (common-fields.md 5.3).
oneOf · oneOf[0] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · …
recursion truncated at depth 8; see source schema for full shape
stage_changed_at · oneOf[2] · $ref ./time.schema.json#/$defs/nullable_timestamp
Reducer-derived timestamp of the most recent stage transition; MUST NOT be present without stage (common-fields.md 5.3.1).
oneOf · oneOf[0] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · …
recursion truncated at depth 8; see source schema for full shape
title · oneOf[2]
Derived display title from plaintext-visible Strand metadata.title; null when metadata is encrypted or hidden from the service profile.
oneOf · oneOf[0] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · …
recursion truncated at depth 8; see source schema for full shape
summary · oneOf[2]
Derived display summary from plaintext-visible Strand metadata.summary; null when metadata is encrypted or hidden from the service profile.
oneOf · oneOf[0] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · …
recursion truncated at depth 8; see source schema for full shape
topic · object · $ref ./strand.schema.json#/$defs/strand_topic
* space_id · …
recursion truncated at depth 8; see source schema for full shape
* rank · …
recursion truncated at depth 8; see source schema for full shape
board_space_id · string | null
Derived board Space id from strand_position; not canonical Strand object state.
pattern: ^ak:space:[A-Za-z0-9_-]{44}$
list_space_id · string | null
Derived list Space id from strand_position; not canonical Strand object state.
pattern: ^ak:space:[A-Za-z0-9_-]{44}$
rank · string | null
Derived rank within list_space_id from strand_position.
assigned_actor_ids · array<$ref ./common-ids.schema.json#/$defs/actor_id>
Derived current full ActorIds from visible active Relation(relation_kind=assigned_to, from_ref=strand_id), preserving Station identity. Empty or absent means the Strand is unassigned for this projection caller. This is read-model state, not canonical Strand object metadata.
items · …
recursion truncated at depth 8; see source schema for full shape
assigned_to_relations · array<$ref #/$defs/ProjectionAssignedToRelation>
Read-only active assigned_to Relation edges backing assigned_actor_ids. Clients use relation_id to tombstone assignments.
items · …
recursion truncated at depth 8; see source schema for full shape
created_by · oneOf[2]
oneOf · oneOf[0] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · …
recursion truncated at depth 8; see source schema for full shape
created_at · oneOf[2] · $ref ./time.schema.json#/$defs/nullable_timestamp
oneOf · oneOf[0] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · …
recursion truncated at depth 8; see source schema for full shape
updated_by · oneOf[2]
oneOf · oneOf[0] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · …
recursion truncated at depth 8; see source schema for full shape
updated_at · oneOf[2] · $ref ./time.schema.json#/$defs/nullable_timestamp
oneOf · oneOf[0] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · …
recursion truncated at depth 8; see source schema for full shape
* is_default · boolean
DERIVED, not independent storage: true iff strand_id == the parent Realm projection's default_strand_id (the authoritative pointer written by ak.realm.set_default_strand). The projector computes this from Realm.default_strand_id; a stale/dangling pointer never resolves to is_default=true because the reducer rejects set_default_strand against a non-existent Strand. Clients identify the Realm's default discussion Strand deterministically from this flag (or equivalently from Realm.default_strand_id) and MUST NOT infer the default from any Strand-reuses-Realm-token or other implementation detail. See zh/models/strand-and-message.md (default-Strand discovery).
* total · integer
next_cursor · string
pattern: ^ak:cursor:[A-Za-z0-9_-]+$
* has_more · boolean
anyOf · anyOf[47] · object · $ref #/$defs/StrandWatchCurrentRequestBody
Exact self watch selector. It cannot enumerate watchers or supply an expected CAS value.
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* strand_id · string · $ref ./event-payload.schema.json#/$defs/strand_id
pattern: ^ak:strand:[A-Za-z0-9_-]{44}$
* watcher_actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind · const "account"
enum: "account"
* account_id · $ref #/$defs/account_id · $ref #/$defs/account_id
oneOf · oneOf[1] · object
* kind · const "service"
enum: "service"
* service_id · $ref #/$defs/did_core_id · $ref #/$defs/did_core_id
anyOf · anyOf[48] · oneOf[2] · $ref #/$defs/StrandWatchCurrentOutcome
A verified never-written fact is distinct from a written result whose value was cleared to null.
oneOf · oneOf[0] · object · $ref #/$defs/StrandWatchCurrentNeverWritten
* status · const "never_written"
enum: "never_written"
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* governance_generation · integer
* stream_head · object · $ref ./realm-commit.schema.json#/$defs/stream_head
* stream_ref · $ref #/$defs/stream_ref · $ref #/$defs/stream_ref
* stream_position · integer
* commit_id · string · $ref ./common-ids.schema.json#/$defs/realm_commit_id
Content-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern: ^ak:realm_commit:[A-Za-z0-9_-]{44}$
* selector · object · $ref ./typed-current-result.schema.json#/$defs/strand_watch_result/properties/selector
* kind · const "strand_watch"
enum: "strand_watch"
* strand_id · string · $ref ./event-payload.schema.json#/$defs/strand_id
pattern: ^ak:strand:[A-Za-z0-9_-]{44}$
* watcher_actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object · $ref #/$defs/StrandWatchCurrentPresent
* status · const "current"
enum: "current"
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* governance_generation · integer
* stream_head · object · $ref ./realm-commit.schema.json#/$defs/stream_head
* stream_ref · $ref #/$defs/stream_ref · $ref #/$defs/stream_ref
* stream_position · integer
* commit_id · string · $ref ./common-ids.schema.json#/$defs/realm_commit_id
Content-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern: ^ak:realm_commit:[A-Za-z0-9_-]{44}$
* result · object · $ref ./typed-current-result.schema.json#/$defs/strand_watch_result
* selector · object
* kind · …
recursion truncated at depth 8; see source schema for full shape
* strand_id · …
recursion truncated at depth 8; see source schema for full shape
* watcher_actor_id · …
recursion truncated at depth 8; see source schema for full shape
* source_stream_ref · oneOf[3] · $ref ./realm-commit.schema.json#/$defs/stream_ref
Closed visibility-stream selector. Realm, each Circle and each Sidecar have independent continuous positions so hidden scopes do not leak through global gaps.
oneOf · oneOf[0] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[2] · …
recursion truncated at depth 8; see source schema for full shape
* revision · $ref #/$defs/revision · $ref #/$defs/revision
* value · $ref #/$defs/strand_watch_value · $ref #/$defs/strand_watch_value
anyOf · anyOf[49] · object · $ref #/$defs/ServiceRegistrationEnsureRequestBody
* service_kind · string (enum) · $ref #/$defs/ServiceRegistrationKey/properties/service_kind
enum: "station" "identity_registry"
* public_base_url · string (uri) · format=uri · $ref #/$defs/ServiceRegistrationKey/properties/public_base_url
Canonical service base URL: lower-case scheme and host, no query or fragment, normalized path, and exactly one trailing slash. Production deployments MUST use https; explicit development deployments MAY use http.
pattern: ^https?://[^?#]+/$
* did · string · $ref ./common-ids.schema.json#/$defs/did
Canonical bare DID used for registration, DID method resolution and owner-published current resolution. It contains no path, query or fragment and MUST project through the registered method adapter to exactly one did_core_id.
pattern: ^did:[a-z0-9]+:[^\s/?#]+$
* inception_operation · object · $ref #/$defs/ServiceWebvhInceptionOperation
* versionId · string
pattern: ^1-[1-9A-HJ-NP-Za-km-z]+$
* versionTime · string (date-time) · format=date-time
* parameters · object · $ref #/$defs/ServiceWebvhInceptionParameters
* scid · string
pattern: ^[1-9A-HJ-NP-Za-km-z]+$
* method · const "did:webvh:1.0"
enum: "did:webvh:1.0"
* updateKeys · array<string>
Exactly one active service-controlled update key. On a rotation entry it MUST open the previous entry's sole nextKeyHashes commitment; spent keys MUST NOT be reused.
items · …
recursion truncated at depth 8; see source schema for full shape
* nextKeyHashes · array<string>
Exactly one sha2-256 multihash/Base58BTC commitment to a next update key generated and durably held by the service. Missing or mismatched commitments fail closed as service_prerotation_invalid.
items · …
recursion truncated at depth 8; see source schema for full shape
* state · object · $ref #/$defs/ServiceDidDocument
* @context · array<string (uri)>
items · …
recursion truncated at depth 8; see source schema for full shape
* id · string · $ref ./common-ids.schema.json#/$defs/webvh_did
Canonical bare did:webvh identifier used at method-native registration, document and evidence boundaries. Role admission is enforced separately.
pattern: ^did:webvh:[^\s:/?#]+:[^\s/?#]+$
alsoKnownAs · array<string (uri)>
items · …
recursion truncated at depth 8; see source schema for full shape
* verificationMethod · array<$ref #/$defs/ServiceDidVerificationMethod>
items · …
recursion truncated at depth 8; see source schema for full shape
* authentication · array<string>
items · …
recursion truncated at depth 8; see source schema for full shape
* assertionMethod · array<string>
items · …
recursion truncated at depth 8; see source schema for full shape
* service · array<$ref #/$defs/ServiceDidEndpoint>
items · …
recursion truncated at depth 8; see source schema for full shape
* proof · array<$ref #/$defs/ServiceWebvhDataIntegrityProof>
items · object · $ref #/$defs/ServiceWebvhDataIntegrityProof
* type · …
recursion truncated at depth 8; see source schema for full shape
* cryptosuite · …
recursion truncated at depth 8; see source schema for full shape
* verificationMethod · …
recursion truncated at depth 8; see source schema for full shape
* proofPurpose · …
recursion truncated at depth 8; see source schema for full shape
* proofValue · …
recursion truncated at depth 8; see source schema for full shape
* idempotency_key · string · $ref ./principal-operations.schema.json#/$defs/opaque_id
Bounded opaque caller-chosen correlation string used only to relate audit records for one ensure attempt. It is deliberately outside the ak: typed-ID namespace and MUST NOT be parsed by the typed-ID parser or treated as an object identity. Registration identity is the canonical (service_kind, public_base_url) key that Provider persistence enforces with UNIQUE(service_kind, public_base_url), and the single idempotency authority for this operation is the operation registry's idempotency_mechanism=object_id; this field never establishes a second one.
previous_receipt · oneOf[2]
oneOf · oneOf[0] · object · $ref #/$defs/ServiceRegistrationReceipt
Provider-signed stable service-registration receipt. registration_receipt_id is ak:service_registration_receipt:<lowercase hex SHA-256(canonical_json(receipt claims))>. service_id is the projected did_core_id and did is the verified DID. proof is a detached JWS over the ak.service_registration_receipt_proof.v1 binding object; consumers verify the provider through its own resolution evidence.
* registration_receipt_id · string
pattern: ^ak:service_registration_receipt:[0-9a-f]{64}$
* registration_key · object · $ref #/$defs/ServiceRegistrationKey
* service_kind · …
recursion truncated at depth 8; see source schema for full shape
* public_base_url · …
recursion truncated at depth 8; see source schema for full shape
* service_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* did · string · $ref ./common-ids.schema.json#/$defs/did
Canonical bare DID used for registration, DID method resolution and owner-published current resolution. It contains no path, query or fragment and MUST project through the registered method adapter to exactly one did_core_id.
pattern: ^did:[a-z0-9]+:[^\s/?#]+$
* version_id · string
pattern: ^(?!ak:)
* log_head_digest · string
pattern: ^sha256:[0-9a-f]{64}$
* control_key_digest · string
Digest of the active control/update public key at version_id; this is not the next-key commitment or private recovery material.
pattern: ^sha256:[0-9a-f]{64}$
* issued_at · string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
* provider_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* proof · object · $ref ./event-envelope.schema.json#/$defs/proof
Generic detached-JWS proof shape reused by non-Event schemas (snapshot signature, snapshot witness attestations, identity receipts, handle claims, etc.). MUST NOT be used as the shape of Event Envelope `producer_proof` — Event proofs reference $defs/event_proof and bind canonical Event bytes via `event_digest`. Non-Event signed objects MUST define an object-family signing-context constant and include it in the canonical proof binding object with payload_digest; the context constant is not a wire field in this generic shape. drift detection: `payload_digest#event_proof` in forbidden-wire-fields.json is the hard-reject mirror of this rule. New non-Event signed objects MAY $ref this shape; new signed Event-shaped objects MUST instead $ref event_proof.
* kind · …
recursion truncated at depth 8; see source schema for full shape
* verification_method · …
recursion truncated at depth 8; see source schema for full shape
* payload_digest · …
recursion truncated at depth 8; see source schema for full shape
* created_at · …
recursion truncated at depth 8; see source schema for full shape
domain · …
recursion truncated at depth 8; see source schema for full shape
audience · …
recursion truncated at depth 8; see source schema for full shape
proof_purpose · …
recursion truncated at depth 8; see source schema for full shape
* jws · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · null
anyOf · anyOf[50] · object · $ref #/$defs/ServiceRegistrationOutcome
* did_document · object · $ref #/$defs/ServiceDidDocument
* @context · array<string (uri)>
items · string (uri) · format=uri
* id · string · $ref ./common-ids.schema.json#/$defs/webvh_did
Canonical bare did:webvh identifier used at method-native registration, document and evidence boundaries. Role admission is enforced separately.
pattern: ^did:webvh:[^\s:/?#]+:[^\s/?#]+$
alsoKnownAs · array<string (uri)>
items · string (uri) · format=uri
* verificationMethod · array<$ref #/$defs/ServiceDidVerificationMethod>
items · object · $ref #/$defs/ServiceDidVerificationMethod
* id · …
recursion truncated at depth 8; see source schema for full shape
* type · …
recursion truncated at depth 8; see source schema for full shape
* controller · …
recursion truncated at depth 8; see source schema for full shape
* publicKeyMultibase · …
recursion truncated at depth 8; see source schema for full shape
* authentication · array<string>
items · string
pattern: ^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$
* assertionMethod · array<string>
items · string
pattern: ^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$
* service · array<$ref #/$defs/ServiceDidEndpoint>
items · object · $ref #/$defs/ServiceDidEndpoint
* id · …
recursion truncated at depth 8; see source schema for full shape
* type · …
recursion truncated at depth 8; see source schema for full shape
* serviceKind · …
recursion truncated at depth 8; see source schema for full shape
* serviceEndpoint · …
recursion truncated at depth 8; see source schema for full shape
* registration_receipt · object · $ref #/$defs/ServiceRegistrationReceipt
Provider-signed stable service-registration receipt. registration_receipt_id is ak:service_registration_receipt:<lowercase hex SHA-256(canonical_json(receipt claims))>. service_id is the projected did_core_id and did is the verified DID. proof is a detached JWS over the ak.service_registration_receipt_proof.v1 binding object; consumers verify the provider through its own resolution evidence.
* registration_receipt_id · string
pattern: ^ak:service_registration_receipt:[0-9a-f]{64}$
* registration_key · object · $ref #/$defs/ServiceRegistrationKey
* service_kind · string (enum)
enum: "station" "identity_registry"
* public_base_url · string (uri) · format=uri
Canonical service base URL: lower-case scheme and host, no query or fragment, normalized path, and exactly one trailing slash. Production deployments MUST use https; explicit development deployments MAY use http.
pattern: ^https?://[^?#]+/$
* service_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* did · string · $ref ./common-ids.schema.json#/$defs/did
Canonical bare DID used for registration, DID method resolution and owner-published current resolution. It contains no path, query or fragment and MUST project through the registered method adapter to exactly one did_core_id.
pattern: ^did:[a-z0-9]+:[^\s/?#]+$
* version_id · string
pattern: ^(?!ak:)
* log_head_digest · string
pattern: ^sha256:[0-9a-f]{64}$
* control_key_digest · string
Digest of the active control/update public key at version_id; this is not the next-key commitment or private recovery material.
pattern: ^sha256:[0-9a-f]{64}$
* issued_at · string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
* provider_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* proof · object · $ref ./event-envelope.schema.json#/$defs/proof
Generic detached-JWS proof shape reused by non-Event schemas (snapshot signature, snapshot witness attestations, identity receipts, handle claims, etc.). MUST NOT be used as the shape of Event Envelope `producer_proof` — Event proofs reference $defs/event_proof and bind canonical Event bytes via `event_digest`. Non-Event signed objects MUST define an object-family signing-context constant and include it in the canonical proof binding object with payload_digest; the context constant is not a wire field in this generic shape. drift detection: `payload_digest#event_proof` in forbidden-wire-fields.json is the hard-reject mirror of this rule. New non-Event signed objects MAY $ref this shape; new signed Event-shaped objects MUST instead $ref event_proof.
* kind · string (enum)
Generic detached JWS proof over a canonical non-Event payload binding object that includes an object-family context constant.
enum: "detached_jws"
* verification_method · string
DID URL of the signing key for this non-Event detached proof. Same pattern as $defs/event_proof.verification_method; semantics are decoupled from Event proof (see $defs/event_proof for the Event-only shape).
pattern: ^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$
* payload_digest · $ref #/$defs/digest · $ref #/$defs/digest
Generic non-Event detached-proof hash. This $defs/proof shape is reused by non-Event schemas; Event.properties.producer_proof references $defs/event_proof and MUST use event_digest instead.
* created_at · $ref #/$defs/timestamp · $ref #/$defs/timestamp
domain · string
audience · oneOf[2]
oneOf · oneOf[0] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · …
recursion truncated at depth 8; see source schema for full shape
proof_purpose · string (enum)
Optional role discriminator for non-Event proofs. HandleClaim core, status and revocation carriers make issuer_attestation, holder_acceptance, status_attestation and revocation_authorization load-bearing. governance_authorization marks a resource-governance-key authorization (directory withdraw/takedown-appeal, discovery-directory.md 8.7.1). Generic proof consumers ignore it unless their object-family contract makes it load-bearing.
enum: "issuer_attestation" "holder_acceptance" "status_attestation" "revocation_authorization" "governance_authorization"
* jws · string
pattern: ^[A-Za-z0-9_-]+\.\.[A-Za-z0-9_-]+$
* created · boolean
anyOf · anyOf[51] · object · $ref #/$defs/SessionGrantIntrospectOutcome
allOf · allOf[0] · ?
* active · boolean
Whether the grant is currently valid for the requested audience. READ-ONLY: introspection never consumes the grant.
* status · string (enum)
enum: "active" "revoked" "superseded" "expired" "locked" "suspended" "audience_mismatch" "proof_required" "invalid_proof" "not_found"
* proof_required · boolean
Whether an additional S2S holder proof is required to confirm the grant active for this introspection request. Default Station grant+DPoP validation uses the request DPoP instead of this field.
* one_time_use_consumed · boolean
Always false: introspection is read-only and never consumes single-use state (rotation is the refresh endpoint's job).
grant · object · $ref #/$defs/SessionGrantIntrospectGrant
Non-secret grant metadata returned to the validating Station. Never includes the grant JWT, refresh token, or session private key.
allOf · allOf[0] · ?
allOf · allOf[1] · ?
allOf · allOf[2] · ?
allOf · allOf[3] · ?
* id · string · $ref ./common-ids.schema.json#/$defs/session_grant_id
pattern: ^ak:session_grant:[A-Za-z0-9_-]{44}$
* issuer_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id · $ref #/$defs/did_core_id · $ref #/$defs/did_core_id
* station_id · $ref #/$defs/did_core_id · $ref #/$defs/did_core_id
device_id · string · $ref ./common-ids.schema.json#/$defs/device_id
pattern: ^ak:device:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$
* audience_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* scopes · array<string>
items · string
* expires_at · string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
revoked_at · string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
* revocation_ref · string
* session_public_key · string
Session signing key (JWK) for RFC 9421 PoP verification on /_arkret/self/* (api-conventions §3.2). Server-to-server only.
* cnf_jkt · string
RFC 7638 JWK SHA-256 thumbprint of the holder (DPoP) key the grant is bound to (cnf.jkt); the Station uses it to verify the per-request DPoP proof on /_arkret/self/* (api-conventions §3.3). Server-to-server only.
* credential_class · string (enum) · $ref #/$defs/SessionGrantCredentialClass
Closed credential class. recovery_session is a <=15 minute, non-refreshable, DPoP-bound candidate-device grant restricted to the exact recovery operation set; recovery completion issues a distinct standard grant.
enum: "standard" "recovery_session"
* holder_binding · oneOf[3] · $ref ./principal-operations.schema.json#/$defs/session_grant_holder_binding
Required closed accepted human-device, recovery candidate-device, or Agent-runtime holder binding.
oneOf · oneOf[0] · object
* kind · …
recursion truncated at depth 8; see source schema for full shape
* device_binding · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* kind · …
recursion truncated at depth 8; see source schema for full shape
* agent_id · …
recursion truncated at depth 8; see source schema for full shape
* agent_key_authorization_ref · …
recursion truncated at depth 8; see source schema for full shape
* verification_method · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[2] · object
* kind · …
recursion truncated at depth 8; see source schema for full shape
* device_id · …
recursion truncated at depth 8; see source schema for full shape
device_binding · object · $ref #/$defs/SessionGrantDeviceBinding
Authorization state committed into a standard device grant. An Account Authority MUST populate it verbatim from the Station TCB current-device decision, which is the only source of the origin-derived authorization Event and generation; it MUST NOT be taken from client input, a local cache or a private lookup. Stations compare it with the current active device generation on admission.
* device_id · string · $ref ./common-ids.schema.json#/$defs/device_id
pattern: ^ak:device:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$
* authorization_event_id · string
pattern: ^ak:event:[A-Za-z0-9_-]{44}$
* model_generation_ref · integer · $ref ./recovery-session.schema.json#/$defs/pcr_generation_ref
PCR-local monotonic generation. It MUST NOT equal or be derived from a DID versionId.
anyOf · anyOf[52] · object · $ref #/$defs/SessionGrantIntrospectRequestBody
Server-to-server session-grant introspection request. Exactly one of id / grant_jwt identifies the grant.
oneOf · oneOf[0] · ?
oneOf · oneOf[1] · ?
id · string · $ref ./common-ids.schema.json#/$defs/session_grant_id
Grant id. Mutually exclusive with grant_jwt.
pattern: ^ak:session_grant:[A-Za-z0-9_-]{44}$
grant_jwt · string
The signed grant JWT to introspect. Mutually exclusive with id.
audience_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
proof · object
Optional S2S holder confirmation signed by the session key bound into the grant. Stations validating /_arkret/self/* grant+DPoP requests do not require a client-carried introspection proof; they verify the request DPoP locally against the returned cnf_jkt.
* challenge · string
* proof_jwt · string
JWS over ak.session_grant.introspection_proof.v1 claims (session_grant_id, grant_jwt_digest, audience, challenge, issued_at, expires_at).
anyOf · anyOf[53] · object · $ref #/$defs/SessionGrantOutcome
* account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id · $ref #/$defs/did_core_id · $ref #/$defs/did_core_id
* station_id · $ref #/$defs/did_core_id · $ref #/$defs/did_core_id
device_id · string
pattern: ^ak:device:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$
* session_grant · string
Short-lived bearer/session grant bound to the requested principal, device and audience.
* expires_at · string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
* session_grant_id · string · $ref ./common-ids.schema.json#/$defs/session_grant_id
Stable id of the issued or rotated session grant. Returned for every grant so the client can reference, refresh, introspect or revoke this exact grant without re-parsing the opaque session_grant.
pattern: ^ak:session_grant:[A-Za-z0-9_-]{44}$
* session_public_key · string (canonical-public-jwk-jcs) · format=canonical-public-jwk-jcs
JWK of the holder/session key the grant is bound to (the device holder key). The client needs this to perform RFC 9421 PoP and to derive the DPoP cnf.jkt for /_arkret/self/* requests (api-conventions.md §3.2 / §3.3); returning it avoids a mandatory introspect round-trip before the first self-path request.
* audience_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* granted_scope · array<string>
items · string
previous_session_grant_id · string · $ref ./common-ids.schema.json#/$defs/session_grant_id
Present only on refresh. The predecessor grant atomically superseded by this successor.
pattern: ^ak:session_grant:[A-Za-z0-9_-]{44}$
anyOf · anyOf[54] · oneOf[2] · $ref #/$defs/SessionGrantRefreshRequestBody
Closed human-versus-Agent SessionGrant rotation union. Neither branch accepts a client-generated challenge or a generic proof_kind enum.
oneOf · oneOf[0] · object · $ref #/$defs/HumanSessionGrantRefreshRequest
* grant_jwt · string
Near-expiry human DPoP-bound SessionGrant presented as Authorization: DPoP plus a matching DPoP proof.
audience_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* device_id · string · $ref ./common-ids.schema.json#/$defs/device_id
pattern: ^ak:device:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$
* accepted_device_possession_proof · object · $ref #/$defs/AcceptedDevicePossessionProof
Accepted-device Ed25519 possession proof shared by human SessionGrant issue and refresh. The signature covers utf8('ak.session_grant_accepted_device_possession_proof.v1\n') followed by RFC 8785 JCS of this complete object with signature omitted. It is not a server challenge: freshness comes from the <=300 second signed window, the one-time account handoff or predecessor grant, the issuer request identity, and issuer-ledger exact replay. The origin Station MUST verify this proof with the durable current accepted-device key in the same linearization that evaluates current authorization.
allOf · allOf[0] · ?
* context · const "ak.session_grant_accepted_device_possession_proof.v1"
enum: "ak.session_grant_accepted_device_possession_proof.v1"
* purpose · string (enum)
enum: "session_grant_issue" "session_grant_refresh"
request_id · string
pattern: ^ak:request:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$
account_subject · string
pattern: ^sha256:[0-9a-f]{64}$
account_handoff_grant_digest · string
SHA-256 digest of the exact opaque DPoP-bound account_handoff_grant presented in Authorization; the credential itself MUST NOT enter the proof or logs.
pattern: ^sha256:[0-9a-f]{64}$
predecessor_session_grant_id · string · $ref ./common-ids.schema.json#/$defs/session_grant_id
pattern: ^ak:session_grant:[A-Za-z0-9_-]{44}$
* account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id · …
recursion truncated at depth 8; see source schema for full shape
* station_id · …
recursion truncated at depth 8; see source schema for full shape
* device_id · string · $ref ./common-ids.schema.json#/$defs/device_id
pattern: ^ak:device:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$
* audience_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* holder_jkt · string
RFC 7638 thumbprint of the DPoP holder key for the handoff or predecessor SessionGrant.
pattern: ^[A-Za-z0-9_-]{43}$
* session_intent_digest · string
Digest of the complete canonical immutable issue or refresh intent.
pattern: ^sha256:[0-9a-f]{64}$
* issued_at · string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
* expires_at · string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
* verification_method · string
DID URL of the accepted device key; its fragment MUST identify device_id and its bare did MUST project to account_id.principal_id.
pattern: ^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$
* signature · string
64-byte raw Ed25519 signature encoded as canonical unpadded base64url.
pattern: ^[A-Za-z0-9_-]{86}$
oneOf · oneOf[1] · object · $ref #/$defs/AgentSessionGrantRefreshRequest
Agent rotation binds the predecessor grant's agent_id, accepted agent_key_authorization_ref and proof.verification_method. Agent MLS endpoints have no device_id; a refresh carrying one is invalid.
* grant_jwt · string
Near-expiry Agent DPoP-bound SessionGrant presented as Authorization: DPoP plus a matching DPoP proof.
audience_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* principal_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* agent_key_authorization_ref · string · $ref ./account-operations.schema.json#/$defs/event_id
pattern: ^ak:event:[A-Za-z0-9_-]{44}$
* agent_session_refresh_proof · object · $ref #/$defs/AgentSessionRefreshProof
Current Agent runtime-key proof for SessionGrant rotation. It is a distinct branch from accepted human-device PoP and carries no client-generated challenge or polymorphic proof_kind.
* context · const "ak.agent_session_refresh_proof.v1"
enum: "ak.agent_session_refresh_proof.v1"
* request_canonical_digest · string
pattern: ^sha256:[0-9a-f]{64}$
* audience_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* issued_at · string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
* expires_at · string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
* verification_method · string
pattern: ^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$
* signature · string
pattern: ^[A-Za-z0-9_-]{86}$
anyOf · anyOf[55] · object · $ref #/$defs/SessionGrantReplayExpiredProblem
Closed RFC 9457 Problem Details extension members for session_grant_replay_expired. The named issuer-ledger record remains authoritative and no replacement grant is created under the same request identity.
* session_grant_id · string · $ref ./common-ids.schema.json#/$defs/session_grant_id
pattern: ^ak:session_grant:[A-Za-z0-9_-]{44}$
* state · const "expired"
Retained on purpose: this is an RFC 9457 Problem Details extension member on the failure path and names the issuer-ledger state that caused the rejection, so the problem document stays self-describing next to SessionGrantReplayTerminalProblem. It is not a success-only outcome constant.
enum: "expired"
anyOf · anyOf[56] · object · $ref #/$defs/SessionGrantReplayTerminalProblem
Closed RFC 9457 Problem Details extension members for session_grant_replay_terminal. The state is an exact durable issuer-ledger terminal state and no replacement grant is created under the same request identity.
* session_grant_id · string · $ref ./common-ids.schema.json#/$defs/session_grant_id
pattern: ^ak:session_grant:[A-Za-z0-9_-]{44}$
* state · string (enum)
enum: "revoked" "superseded"
anyOf · anyOf[57] · oneOf[3] · $ref #/$defs/SessionGrantRequestBody
Closed returning-human, Agent runtime or fresh-device recovery issuance union. OIDC authorization codes are consumed only by account_handoff_request_body and never by this operation.
oneOf · oneOf[0] · object · $ref #/$defs/HumanSessionGrantRequest
Returning-human issuance from an already bound account. Authorization is the DPoP-bound account_handoff_grant plus matching per-request DPoP; the body deliberately carries neither a second holder signature nor requested_scope.
* request_id · string
pattern: ^ak:request:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$
* principal_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* device_id · string · $ref ./common-ids.schema.json#/$defs/device_id
pattern: ^ak:device:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$
* audience_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* accepted_device_possession_proof · object · $ref #/$defs/AcceptedDevicePossessionProof
Accepted-device Ed25519 possession proof shared by human SessionGrant issue and refresh. The signature covers utf8('ak.session_grant_accepted_device_possession_proof.v1\n') followed by RFC 8785 JCS of this complete object with signature omitted. It is not a server challenge: freshness comes from the <=300 second signed window, the one-time account handoff or predecessor grant, the issuer request identity, and issuer-ledger exact replay. The origin Station MUST verify this proof with the durable current accepted-device key in the same linearization that evaluates current authorization.
allOf · allOf[0] · ?
* context · const "ak.session_grant_accepted_device_possession_proof.v1"
enum: "ak.session_grant_accepted_device_possession_proof.v1"
* purpose · string (enum)
enum: "session_grant_issue" "session_grant_refresh"
request_id · string
pattern: ^ak:request:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$
account_subject · string
pattern: ^sha256:[0-9a-f]{64}$
account_handoff_grant_digest · string
SHA-256 digest of the exact opaque DPoP-bound account_handoff_grant presented in Authorization; the credential itself MUST NOT enter the proof or logs.
pattern: ^sha256:[0-9a-f]{64}$
predecessor_session_grant_id · string · $ref ./common-ids.schema.json#/$defs/session_grant_id
pattern: ^ak:session_grant:[A-Za-z0-9_-]{44}$
* account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id · …
recursion truncated at depth 8; see source schema for full shape
* station_id · …
recursion truncated at depth 8; see source schema for full shape
* device_id · string · $ref ./common-ids.schema.json#/$defs/device_id
pattern: ^ak:device:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$
* audience_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* holder_jkt · string
RFC 7638 thumbprint of the DPoP holder key for the handoff or predecessor SessionGrant.
pattern: ^[A-Za-z0-9_-]{43}$
* session_intent_digest · string
Digest of the complete canonical immutable issue or refresh intent.
pattern: ^sha256:[0-9a-f]{64}$
* issued_at · string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
* expires_at · string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
* verification_method · string
DID URL of the accepted device key; its fragment MUST identify device_id and its bare did MUST project to account_id.principal_id.
pattern: ^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$
* signature · string
64-byte raw Ed25519 signature encoded as canonical unpadded base64url.
pattern: ^[A-Za-z0-9_-]{86}$
oneOf · oneOf[1] · object · $ref #/$defs/AgentSessionGrantRequest
Agent runtime session issuance is bound to principal_id (agent_id), proof.verification_method and the current accepted agent_key_authorization_ref. This closed branch MUST NOT carry a device_id or derive one from the Agent key.
* principal_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* requested_scope · array<string>
items · string
* agent_key_authorization_ref · string
`ak.profile.agent_auth.v1` overlay. Event ref of the accepted `ak.agent.key.authorize` that authorized the runtime key. REQUIRED when `proof.proof_kind="agent_key_proof"`; MUST be omitted for human session grants.
pattern: ^ak:event:[A-Za-z0-9_-]{44}$
* agent_scope_request · object
`ak.profile.agent_auth.v1` overlay. Narrowing hints for the issued session scope. Service-surface requested_scope values are intersected with the immutable provision requested_scope, accepted agent_key_scope and endpoint/resource policy; content actions are additionally intersected with independent effective Realm capability grants, participation, membership, history visibility and E2EE policy. Provision mandatory constraints remain in force at every layer. REQUIRED when `proof.proof_kind="agent_key_proof"`; MUST be omitted for human session grants. `track_names` is a request-side narrowing field only — the materialized session grant MUST express track scope via the canonical `allowed_tracks` constraint, not via a new `track_names` grant.
realm_ids · array<$ref ./common-ids.schema.json#/$defs/realm_id>
items · …
recursion truncated at depth 8; see source schema for full shape
strand_ids · array<string>
items · …
recursion truncated at depth 8; see source schema for full shape
track_names · array<string>
items · …
recursion truncated at depth 8; see source schema for full shape
requested_scope_disclosure · object · $ref ./agent-requested-scope-disclosure.schema.json
Controller-signed, verifier-bound private disclosure of an Agent's immutable requested_scope. This object is authorization evidence, not a grant. It MUST travel only over an authenticated confidential presentation/operation channel and MUST NOT be written to a public DID Document, durable Realm Event, public registry, pairing code, or notification. The verifier consumes request_id/challenge once, validates the short presentation window, verifies a current controller proof, recomputes the requested-scope commitment against the accepted-at Agent DID commitment, and then applies the Agent ceiling subset rules. After successful one-time admission, an implementation MAY retain the object only as encrypted verifier-private evidence keyed by the recomputed digest, verifier_id and audience.
* schema · const "ak.schema.agent_requested_scope_disclosure.v1"
enum: "ak.schema.agent_requested_scope_disclosure.v1"
* request_id · string
Identifier of the verifier's authenticated private challenge request. It is single-use at verifier_id.
pattern: ^ak:request:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$
* agent_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* controller_principal_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* requested_scope · object · $ref ./event-payload.schema.json#/$defs/agent_key_scope
Agent scope object with two uses. In POST /_arkret/self/agents requested_scope it is the required immutable global Agent ceiling; in ak.agent.key.authorize it is a per-key ceiling that MAY be narrower but MUST be an actions/resources/constraints subset of the provision ceiling. It is never a capability grant. actions may contain service operation ids and content action tokens; an omitted action can never be restored by a key, Realm grant or session. resources constrain the service surface and may optionally narrow later content resources, but never authorize content by themselves. Provisioning and pairing do not materialize capability grants from this object; effective authority is the intersection of provision ceiling, key ceiling, independent Realm-scoped grants, session request, membership and policy, with participation applied as an additional deny gate.
* actions · …
recursion truncated at depth 8; see source schema for full shape
* resources · …
recursion truncated at depth 8; see source schema for full shape
constraints · …
recursion truncated at depth 8; see source schema for full shape
* verifier_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* audience · string
Exact origin, service audience, or canonical operation audience requested by verifier_id.
* challenge · string
Verifier-generated unpredictable challenge. The (verifier_id, request_id, challenge) tuple is single-use; replay MUST fail closed.
* issued_at · $ref #/$defs/timestamp · $ref #/$defs/timestamp
* expires_at · $ref #/$defs/timestamp · $ref #/$defs/timestamp
Presentation admission expiry. expires_at MUST be later than issued_at and expires_at - issued_at MUST NOT exceed 300 seconds. It does not change the immutable ceiling; it only bounds disclosure delivery/replay.
* proofs · array<$ref ./event-envelope.schema.json#/$defs/proof>
At least one current controller proof. The proof verification method MUST belong to controller_principal_id or one of its currently authorized devices. payload_digest is sha256(canonical_json(this object with proofs omitted)); detached JWS signs canonical_json({context:'ak.agent_requested_scope_disclosure_proof.v1', payload_digest, agent_id, controller_principal_id, verifier_id, audience, challenge, verification_method, created_at}).
items · …
recursion truncated at depth 8; see source schema for full shape
* dpop_binding_proof · object · $ref #/$defs/SessionGrantDpopBindingProof
`ak.profile.agent_auth.v1` overlay. DPoP proof JWT for the holder key that the issued session grant will bind to. REQUIRED when `proof.proof_kind="agent_key_proof"`; the Account Authority verifies the proof and materializes the resulting JWK thumbprint into the issued grant's `cnf.jkt` / session_public_key binding.
* proof_jwt · string
Frozen initial holder proof authenticated by the Agent request digest. HTTP DPoP is fresh per attempt and must bind the same public JWK thumbprint, not necessarily identical JWT bytes. First validation checks both proofs; completed exact ledger replay reuses validated body proof while revalidating fresh HTTP DPoP. See key-management section 3.6.1.
* proof · object
Closed initial Agent proof. Require 0 < expires_at-issued_at <= 300 seconds, issued_at <= now+30 seconds, and now < expires_at for first validation. No additional nonce. Exact completed issuer-ledger replay reuses durable one-shot verification, with fresh matching-holder HTTP DPoP.
* proof_kind · const "agent_key_proof"
enum: "agent_key_proof"
* challenge · string
Runtime-generated canonical unpadded Base64URL challenge with at least 128 bits of cryptographic randomness. Frozen for exact issuance retry; not a pairing handle or a server-issued challenge.
pattern: ^[A-Za-z0-9_-]+$
* request_canonical_digest · string
pattern: ^sha256:[0-9a-f]{64}$
* audience_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* issued_at · string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
* expires_at · string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
* verification_method · string
`ak.profile.agent_auth.v1` overlay. DID URL of the runtime signing key. REQUIRED when `proof_kind="agent_key_proof"`; the verifier MUST parse and adapter-validate its canonical bare did component, require project(did)=principal_id, and then validate the referenced key at the accepted method-history position. A did_core_id MUST NOT be used as a DID URL prefix or concatenated with a fragment. Projection mismatch returns `verification_method_principal_mismatch`. MUST be omitted for human proof kinds.
pattern: ^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$
* signature · string
Canonical unpadded Base64URL raw Ed25519 signature over RFC 8785 JCS of the entire proof with signature omitted; no Event JWS wrapper or extra prefix.
oneOf · oneOf[2] · object · $ref #/$defs/RecoverySessionGrantRequest
Fresh-device existing-principal recovery issuance. Authorization is the Bound AccountHandoff plus matching per-request DPoP. The Account Authority binds this request to its account/principal mapping and does not consume the handoff on success.
* credential_class · const "recovery_session"
enum: "recovery_session"
* request_id · string
pattern: ^ak:request:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$
* principal_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* device_id · string · $ref ./common-ids.schema.json#/$defs/device_id
pattern: ^ak:device:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$
* audience_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
anyOf · anyOf[58] · object · $ref #/$defs/SignalSubmitOutcome
Result of transient Signal admission. accepted=true means the service placed the encrypted envelope on the short-lived rail; it creates no Event, RealmCommit, authority-stream position or durable delivery receipt.
* accepted · boolean
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* envelope_digest · string
Digest of the admitted complete encrypted envelope, used only for short-lived replay suppression and local correlation.
pattern: ^(sha256|blake3):[0-9a-f]{64}$
dispatched_recipient_count · integer
Optional implementation hint for fanout recipients queued locally.
server_received_at · string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
anyOf · anyOf[59] · object · $ref #/$defs/SignedSessionGrantClaims
Canonical signed claims carried by an ak.session.grant JWT. Except for the fixed kind and derived jti, the closed issuance preimage fields are copied from these claims. credential_class and holder_binding are signed and jointly determine the authorization profile; recovery_session is never refreshable or upgradable and recovery completion issues a distinct standard credential. Verifiers MUST RFC 8785-canonicalize the complete claim-derived preimage, recompute SHA-256, prepend the active sha256 suite wire code, derive ak:session_grant:<44-char-token>, and require byte equality with jti. Changing either binding therefore changes the ID.
allOf · allOf[0] · ?
allOf · allOf[1] · ?
* kind · const "ak.session.grant"
enum: "ak.session.grant"
* jti · string · $ref ./common-ids.schema.json#/$defs/session_grant_id
pattern: ^ak:session_grant:[A-Za-z0-9_-]{44}$
* issuer_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* issuance_nonce · string
Canonical unpadded Base64URL encoding of the issuer-generated 256-bit issuance nonce. Exact replay reuses the same nonce, issuance preimage, grant ID and JWT.
pattern: ^[A-Za-z0-9_-]{43}$
* account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id · $ref #/$defs/did_core_id · $ref #/$defs/did_core_id
* station_id · $ref #/$defs/did_core_id · $ref #/$defs/did_core_id
* session_public_key · string (canonical-public-jwk-jcs) · format=canonical-public-jwk-jcs
A supported public JWK serialized as its exact RFC 8785 JCS UTF-8 string. Producers MUST parse and canonicalize input before signing; consumers MUST reject strings whose parsed JWK re-serialization is not byte-identical. Private JWK members are forbidden.
* audience_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* scopes · array<string>
items · string
* not_before · string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
* expires_at · string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
* session_id · string
pattern: ^(?!ak:)
* credential_class · string (enum) · $ref #/$defs/SessionGrantCredentialClass
Closed credential class. recovery_session is a <=15 minute, non-refreshable, DPoP-bound candidate-device grant restricted to the exact recovery operation set; recovery completion issues a distinct standard grant.
enum: "standard" "recovery_session"
device_binding · object · $ref #/$defs/SessionGrantDeviceBinding
Authorization state committed into a standard device grant. An Account Authority MUST populate it verbatim from the Station TCB current-device decision, which is the only source of the origin-derived authorization Event and generation; it MUST NOT be taken from client input, a local cache or a private lookup. Stations compare it with the current active device generation on admission.
* device_id · string · $ref ./common-ids.schema.json#/$defs/device_id
pattern: ^ak:device:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$
* authorization_event_id · string
pattern: ^ak:event:[A-Za-z0-9_-]{44}$
* model_generation_ref · integer · $ref ./recovery-session.schema.json#/$defs/pcr_generation_ref
PCR-local monotonic generation. It MUST NOT equal or be derived from a DID versionId.
* holder_binding · oneOf[3] · $ref ./principal-operations.schema.json#/$defs/session_grant_holder_binding
oneOf · oneOf[0] · object
* kind · const "human_device"
enum: "human_device"
* device_binding · $ref #/$defs/opaque_id · $ref #/$defs/opaque_id
oneOf · oneOf[1] · object
* kind · const "agent_runtime"
enum: "agent_runtime"
* agent_id · $ref #/$defs/did_core_id · $ref #/$defs/did_core_id
* agent_key_authorization_ref · $ref #/$defs/event_id · $ref #/$defs/event_id
* verification_method · string · $ref ./common-ids.schema.json#/$defs/did_url
Arkret verification-method DID URL profile (identity/did-usage-and-verification.md section 2.2): lowercase method name, no query, required fragment, fragment limited to ASCII [A-Za-z0-9._:-]. Every verification_method-family field and every kid/key_ref a schema declares to be a DID URL MUST resolve to exactly this definition; values compare byte-for-byte with no URI normalization or percent-decoding.
pattern: ^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$
oneOf · oneOf[2] · object
* kind · const "recovery_candidate_device"
enum: "recovery_candidate_device"
* device_id · $ref #/$defs/device_id · $ref #/$defs/device_id
proof_kind · string (enum)
enum: "account_handoff" "agent_key_proof"
scope_details · object
anyOf · anyOf[60] · oneOf[2] · $ref #/$defs/CommittedEventView
Caller-scoped, non-durable read representation pairing one RealmCommit with either the exact producer-signed Event or a minimal withheld marker. It has no independent identity, signature or persistence semantics and is never reducer input.
oneOf · oneOf[0] · object
* commit · object · $ref ./realm-commit.schema.json
The only shared Realm acceptance, ordering, finality and replication record. Every visibility scope has an authority-signed predecessor chain.
allOf · allOf[0] · ?
* commit_id · string · $ref ./common-ids.schema.json#/$defs/realm_commit_id
Content-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern: ^ak:realm_commit:[A-Za-z0-9_-]{44}$
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* stream_ref · $ref #/$defs/stream_ref · $ref #/$defs/stream_ref
* stream_position · integer
* previous_commit_ref · oneOf[2]
oneOf · oneOf[0] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · …
recursion truncated at depth 8; see source schema for full shape
* event_ref · string · $ref ./common-ids.schema.json#/$defs/event_id
Complete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern: ^ak:event:[A-Za-z0-9_-]{44}$
* governance_generation · integer
Tenure counter of the governing Station that signed this Commit; it advances only on an accepted ak.realm.governance_station.change. It is not the Realm authority-root delegation generation of typed-current-result.schema.json#/$defs/realm_authority_root_value, which advances only on ak.realm.authority.reset.
* authority_ref · oneOf[2]
oneOf · oneOf[0] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · …
recursion truncated at depth 8; see source schema for full shape
* committed_at · string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
producer_signer_fact_digest · string · $ref ./account-operations.schema.json#/$defs/sha256_digest
Fixed SHA256 over RFC8785 JCS of the original immutable Human or Applet Service producer fact, excluding the outer target coordinate. Freeze before Commit identity/signature and retain with acceptance; exact replay, replica and handoff preserve this original digest.
pattern: ^sha256:[0-9a-f]{64}$
* signature · allOf[2] · $ref ./detached-object-signature.schema.json#/$defs/realm_commit_signature
allOf · allOf[0] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] · …
recursion truncated at depth 8; see source schema for full shape
* event · allOf[2] · $ref ./event-envelope.schema.json#/$defs/shared_event_envelope
allOf · allOf[0] · anyOf[61] · $ref #
Canonical DTOs reachable from current authority-commit operations. Every definition is part of the current operation closure.
anyOf · anyOf[0] · …
recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[1] · …
recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[2] · …
recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[3] · …
recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[4] · …
recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[5] · …
recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[6] · …
recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[7] · …
recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[8] · …
recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[9] · …
recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[10] · …
recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[11] · …
recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[12] · …
recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[13] · …
recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[14] · …
recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[15] · …
recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[16] · …
recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[17] · …
recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[18] · …
recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[19] · …
recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[20] · …
recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[21] · …
recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[22] · …
recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[23] · …
recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[24] · …
recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[25] · …
recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[26] · …
recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[27] · …
recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[28] · …
recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[29] · …
recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[30] · …
recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[31] · …
recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[32] · …
recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[33] · …
recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[34] · …
recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[35] · …
recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[36] · …
recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[37] · …
recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[38] · …
recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[39] · …
recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[40] · …
recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[41] · …
recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[42] · …
recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[43] · …
recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[44] · …
recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[45] · …
recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[46] · …
recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[47] · …
recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[48] · …
recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[49] · …
recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[50] · …
recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[51] · …
recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[52] · …
recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[53] · …
recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[54] · …
recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[55] · …
recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[56] · …
recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[57] · …
recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[58] · …
recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[59] · …
recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[60] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] · object
* kind · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* commit · object · $ref ./realm-commit.schema.json
The only shared Realm acceptance, ordering, finality and replication record. Every visibility scope has an authority-signed predecessor chain.
allOf · allOf[0] · ?
* commit_id · string · $ref ./common-ids.schema.json#/$defs/realm_commit_id
Content-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern: ^ak:realm_commit:[A-Za-z0-9_-]{44}$
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* stream_ref · $ref #/$defs/stream_ref · $ref #/$defs/stream_ref
* stream_position · integer
* previous_commit_ref · oneOf[2]
oneOf · oneOf[0] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · …
recursion truncated at depth 8; see source schema for full shape
* event_ref · string · $ref ./common-ids.schema.json#/$defs/event_id
Complete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern: ^ak:event:[A-Za-z0-9_-]{44}$
* governance_generation · integer
Tenure counter of the governing Station that signed this Commit; it advances only on an accepted ak.realm.governance_station.change. It is not the Realm authority-root delegation generation of typed-current-result.schema.json#/$defs/realm_authority_root_value, which advances only on ak.realm.authority.reset.
* authority_ref · oneOf[2]
oneOf · oneOf[0] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · …
recursion truncated at depth 8; see source schema for full shape
* committed_at · string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
producer_signer_fact_digest · string · $ref ./account-operations.schema.json#/$defs/sha256_digest
Fixed SHA256 over RFC8785 JCS of the original immutable Human or Applet Service producer fact, excluding the outer target coordinate. Freeze before Commit identity/signature and retain with acceptance; exact replay, replica and handoff preserve this original digest.
pattern: ^sha256:[0-9a-f]{64}$
* signature · allOf[2] · $ref ./detached-object-signature.schema.json#/$defs/realm_commit_signature
allOf · allOf[0] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] · …
recursion truncated at depth 8; see source schema for full shape
* event_disclosure · object · $ref #/$defs/EventDisclosure
Caller-scoped marker stating that canonical Event bytes are withheld. It carries no Event identity, reason, digest, preview or reducer input.
* status · const "withheld"
enum: "withheld"
allOf · allOf[1] · object
* kind · string (enum)
enum: "ak.agent.action_approve" "ak.agent.interaction.set" "ak.agent.key.authorize" "ak.agent.key.revoke" "ak.agent.provision" "ak.agent.sidecar.exchange.control" "ak.applet.bridge_error" "ak.applet.discovery" "ak.applet.managed_actor.provision" "ak.applet.registration" "ak.audit.accessed" "ak.audit.erasure_receipt" "ak.call.create" "ak.call.recording.start" "ak.call.state" "ak.capability.grant" "ak.capability.relinquish" "ak.capability.revoke" "ak.circle.archive" "ak.circle.create" "ak.circle.history_access" "ak.circle.member.state" "ak.circle.restore" "ak.circle.tombstone" "ak.circle.update" "ak.consent.grant" "ak.consent.revoke" "ak.contact.accepted" "ak.contact.rejected" "ak.contact.requested" "ak.contact.scope.update" "ak.contact.tombstone" "ak.device.authorize" "ak.device.reanchor" "ak.device.revoke" "ak.direct_conversation.bound" "ak.identity.accountability_grant" "ak.identity.resolution.update" "ak.invite.accept" "ak.invite.cancel" "ak.invite.claim" "ak.invite.create" "ak.invite.revoke" "ak.invite.third_party" "ak.key_backup.active_series" "ak.member.identity.update" "ak.member.state" "ak.message.create" "ak.message.redact" "ak.message.revise" "ak.mimi.room_binding" "ak.mls.commit" "ak.mls.genesis" "ak.moderation.decision" "ak.moderation.decision.lift" "ak.moderation.franking_proof" "ak.morph.archive" "ak.morph.create" "ak.morph.restore" "ak.morph.stage.set" "ak.morph.update" "ak.organization.moderation_policy" "ak.pin.add" "ak.pin.remove" "ak.pin.reorder" "ak.policy.action" "ak.policy.set" "ak.profile.create" "ak.profile.realm_override" "ak.profile.update" "ak.reaction.add" "ak.reaction.remove" "ak.realm.alias" "ak.realm.archive" "ak.realm.asset_privacy_policy" "ak.realm.authority.reset" "ak.realm.create" "ak.realm.destroy" "ak.realm.discovery" "ak.realm.freeze" "ak.realm.governance_station.change" "ak.realm.history_access" "ak.realm.join_rule" "ak.realm.link" "ak.realm.media_service" "ak.realm.organization" "ak.realm.owner.transfer" "ak.realm.plaintext_visible_services" "ak.realm.policy_bundle" "ak.realm.preview_policy" "ak.realm.profile" "ak.realm.read_receipt_policy" "ak.realm.restore" "ak.realm.schema" "ak.realm.search_policy" "ak.realm.set_default_strand" "ak.realm.tombstone" "ak.realm.unfreeze" "ak.redaction" "ak.relation.create" "ak.relation.tombstone" "ak.relation.update" "ak.rsvp.set" "ak.schema.define" "ak.self.agent.deactivate" "ak.self.agent.pause" "ak.self.agent.resume" "ak.self.moderation.report" "ak.sidecar.context.attach" "ak.sidecar.create" "ak.space.archive" "ak.space.create" "ak.space.parent" "ak.space.restore" "ak.space.tombstone" "ak.space.update" "ak.strand.archive" "ak.strand.create" "ak.strand.move" "ak.strand.reorder" "ak.strand.restore" "ak.strand.stage.set" "ak.strand.tracks.update" "ak.strand.update" "ak.strand.watch.set" "ak.view.create" "ak.view.reconcile" "ak.view.update"
oneOf · oneOf[1] · object
* commit · object · $ref ./realm-commit.schema.json
The only shared Realm acceptance, ordering, finality and replication record. Every visibility scope has an authority-signed predecessor chain.
allOf · allOf[0] · ?
* commit_id · string · $ref ./common-ids.schema.json#/$defs/realm_commit_id
Content-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern: ^ak:realm_commit:[A-Za-z0-9_-]{44}$
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* stream_ref · $ref #/$defs/stream_ref · $ref #/$defs/stream_ref
* stream_position · integer
* previous_commit_ref · oneOf[2]
oneOf · oneOf[0] · string · $ref ./common-ids.schema.json#/$defs/realm_commit_id
Content-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern: ^ak:realm_commit:[A-Za-z0-9_-]{44}$
oneOf · oneOf[1] · null
* event_ref · string · $ref ./common-ids.schema.json#/$defs/event_id
Complete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern: ^ak:event:[A-Za-z0-9_-]{44}$
* governance_generation · integer
Tenure counter of the governing Station that signed this Commit; it advances only on an accepted ak.realm.governance_station.change. It is not the Realm authority-root delegation generation of typed-current-result.schema.json#/$defs/realm_authority_root_value, which advances only on ak.realm.authority.reset.
* authority_ref · oneOf[2]
oneOf · oneOf[0] · string · $ref ./common-ids.schema.json#/$defs/event_id
Complete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern: ^ak:event:[A-Za-z0-9_-]{44}$
oneOf · oneOf[1] · string · $ref ./common-ids.schema.json#/$defs/realm_authority_handoff_id
Content-addressed identity of one closed old-to-new Realm authority handoff.
pattern: ^ak:realm_authority_handoff:[A-Za-z0-9_-]{44}$
* committed_at · string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
producer_signer_fact_digest · string · $ref ./account-operations.schema.json#/$defs/sha256_digest
Fixed SHA256 over RFC8785 JCS of the original immutable Human or Applet Service producer fact, excluding the outer target coordinate. Freeze before Commit identity/signature and retain with acceptance; exact replay, replica and handoff preserve this original digest.
pattern: ^sha256:[0-9a-f]{64}$
* signature · allOf[2] · $ref ./detached-object-signature.schema.json#/$defs/realm_commit_signature
allOf · allOf[0] · anyOf[61] · $ref #
Canonical DTOs reachable from current authority-commit operations. Every definition is part of the current operation closure.
anyOf · anyOf[0] · object · $ref #/$defs/AcceptedDevicePossessionProof
Accepted-device Ed25519 possession proof shared by human SessionGrant issue and refresh. The signature covers utf8('ak.session_grant_accepted_device_possession_proof.v1\n') followed by RFC 8785 JCS of this complete object with signature omitted. It is not a server challenge: freshness comes from the <=300 second signed window, the one-time account handoff or predecessor grant, the issuer request identity, and issuer-ledger exact replay. The origin Station MUST verify this proof with the durable current accepted-device key in the same linearization that evaluates current authorization.
allOf · allOf[0] · ?
* context · const "ak.session_grant_accepted_device_possession_proof.v1"
enum: "ak.session_grant_accepted_device_possession_proof.v1"
* purpose · string (enum)
enum: "session_grant_issue" "session_grant_refresh"
request_id · string
pattern: ^ak:request:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$
account_subject · string
pattern: ^sha256:[0-9a-f]{64}$
account_handoff_grant_digest · string
SHA-256 digest of the exact opaque DPoP-bound account_handoff_grant presented in Authorization; the credential itself MUST NOT enter the proof or logs.
pattern: ^sha256:[0-9a-f]{64}$
predecessor_session_grant_id · string · $ref ./common-ids.schema.json#/$defs/session_grant_id
pattern: ^ak:session_grant:[A-Za-z0-9_-]{44}$
* account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id · $ref #/$defs/did_core_id · $ref #/$defs/did_core_id
* station_id · $ref #/$defs/did_core_id · $ref #/$defs/did_core_id
* device_id · string · $ref ./common-ids.schema.json#/$defs/device_id
pattern: ^ak:device:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$
* audience_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* holder_jkt · string
RFC 7638 thumbprint of the DPoP holder key for the handoff or predecessor SessionGrant.
pattern: ^[A-Za-z0-9_-]{43}$
* session_intent_digest · string
Digest of the complete canonical immutable issue or refresh intent.
pattern: ^sha256:[0-9a-f]{64}$
* issued_at · string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
* expires_at · string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
* verification_method · string
DID URL of the accepted device key; its fragment MUST identify device_id and its bare did MUST project to account_id.principal_id.
pattern: ^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$
* signature · string
64-byte raw Ed25519 signature encoded as canonical unpadded base64url.
pattern: ^[A-Za-z0-9_-]{86}$
anyOf · anyOf[1] · oneOf[2] · $ref #/$defs/ActorPrivateEventSubmitOutcome
Closed outcome of ak.self.actor_private_events.command.submit.v1, discriminated by event_kind. accepted_event_id is the event_id of the accepted Event, and an exact retry returns the first stored outcome. Only ak.device.push_route carries the accepted per-route revision its next write must name as expected_server_revision. No RealmCommit exists for these writes.
oneOf · oneOf[0] · object
* event_kind · const "ak.device.push_route"
enum: "ak.device.push_route"
* accepted_event_id · string · $ref #/$defs/EventId
pattern: ^ak:event:[A-Za-z0-9_-]{44}$
* revision · integer
oneOf · oneOf[1] · object
* event_kind · string (enum)
enum: "ak.agent.action_reject" "ak.agent.action_request" "ak.agent.draft.propose"
* accepted_event_id · string · $ref #/$defs/EventId
pattern: ^ak:event:[A-Za-z0-9_-]{44}$
anyOf · anyOf[2] · object · $ref #/$defs/ActorPrivateEventSubmitRequestBody
Request of ak.self.actor_private_events.command.submit.v1: exactly one caller-signed actor-private Event of a kind that has no dedicated submit operation. The service validates the exact Event bytes and MUST NOT rebuild the payload or co-sign. No approval sidecar exists because no approval layer applies to these kinds. zh/models/actor-private-effects.md section 2.1.
* event · object · $ref ./event-envelope.schema.json
Closed producer-signed Event. Shared persistent Events become final only when the current Realm governance Station issues a RealmCommit in the derived Realm, Circle, or Sidecar stream.
allOf · allOf[0] · ?
allOf · allOf[1] · ?
allOf · allOf[2] · ?
allOf · allOf[3] · ?
allOf · allOf[4] · ?
allOf · allOf[5] · $ref #/$defs/registered_admission_shape · $ref #/$defs/registered_admission_shape
allOf · allOf[6] · $ref #/$defs/registered_execution_shape · $ref #/$defs/registered_execution_shape
allOf · allOf[7] · ?
allOf · allOf[8] · ?
allOf · allOf[9] · ?
allOf · allOf[10] · ?
allOf · allOf[11] · ?
allOf · allOf[12] · ?
allOf · allOf[13] · ?
allOf · allOf[14] · ?
allOf · allOf[15] · ?
allOf · allOf[16] · ?
allOf · allOf[17] · ?
allOf · allOf[18] · ?
allOf · allOf[19] · ?
allOf · allOf[20] · ?
allOf · allOf[21] · ?
allOf · allOf[22] · ?
allOf · allOf[23] · ?
allOf · allOf[24] · ?
allOf · allOf[25] · ?
allOf · allOf[26] · ?
allOf · allOf[27] · ?
allOf · allOf[28] · ?
allOf · allOf[29] · ?
allOf · allOf[30] · ?
allOf · allOf[31] · ?
allOf · allOf[32] · ?
allOf · allOf[33] · ?
allOf · allOf[34] · ?
allOf · allOf[35] · ?
allOf · allOf[36] · ?
allOf · allOf[37] · ?
allOf · allOf[38] · ?
allOf · allOf[39] · ?
allOf · allOf[40] · ?
allOf · allOf[41] · ?
allOf · allOf[42] · ?
allOf · allOf[43] · ?
allOf · allOf[44] · ?
allOf · allOf[45] · ?
allOf · allOf[46] · ?
allOf · allOf[47] · ?
allOf · allOf[48] · ?
allOf · allOf[49] · ?
allOf · allOf[50] · ?
allOf · allOf[51] · ?
allOf · allOf[52] · ?
allOf · allOf[53] · ?
allOf · allOf[54] · ?
allOf · allOf[55] · ?
allOf · allOf[56] · ?
allOf · allOf[57] · ?
allOf · allOf[58] · ?
allOf · allOf[59] · ?
allOf · allOf[60] · ?
allOf · allOf[61] · ?
allOf · allOf[62] · ?
allOf · allOf[63] · ?
allOf · allOf[64] · ?
allOf · allOf[65] · ?
allOf · allOf[66] · ?
allOf · allOf[67] · ?
allOf · allOf[68] · ?
allOf · allOf[69] · ?
allOf · allOf[70] · ?
allOf · allOf[71] · ?
allOf · allOf[72] · ?
allOf · allOf[73] · ?
allOf · allOf[74] · ?
allOf · allOf[75] · ?
allOf · allOf[76] · ?
allOf · allOf[77] · ?
allOf · allOf[78] · ?
allOf · allOf[79] · ?
allOf · allOf[80] · ?
allOf · allOf[81] · ?
allOf · allOf[82] · ?
allOf · allOf[83] · ?
allOf · allOf[84] · ?
allOf · allOf[85] · ?
allOf · allOf[86] · ?
allOf · allOf[87] · ?
allOf · allOf[88] · ?
allOf · allOf[89] · ?
allOf · allOf[90] · ?
allOf · allOf[91] · ?
allOf · allOf[92] · ?
allOf · allOf[93] · ?
allOf · allOf[94] · ?
allOf · allOf[95] · ?
allOf · allOf[96] · ?
allOf · allOf[97] · ?
allOf · allOf[98] · ?
allOf · allOf[99] · ?
allOf · allOf[100] · ?
allOf · allOf[101] · ?
allOf · allOf[102] · ?
allOf · allOf[103] · ?
allOf · allOf[104] · ?
allOf · allOf[105] · ?
allOf · allOf[106] · ?
allOf · allOf[107] · ?
allOf · allOf[108] · ?
allOf · allOf[109] · ?
allOf · allOf[110] · ?
allOf · allOf[111] · ?
allOf · allOf[112] · ?
allOf · allOf[113] · ?
allOf · allOf[114] · ?
allOf · allOf[115] · ?
allOf · allOf[116] · ?
allOf · allOf[117] · ?
allOf · allOf[118] · ?
allOf · allOf[119] · ?
allOf · allOf[120] · ?
allOf · allOf[121] · ?
allOf · allOf[122] · ?
allOf · allOf[123] · ?
allOf · allOf[124] · ?
allOf · allOf[125] · ?
allOf · allOf[126] · ?
allOf · allOf[127] · ?
allOf · allOf[128] · ?
allOf · allOf[129] · ?
allOf · allOf[130] · ?
allOf · allOf[131] · ?
allOf · allOf[132] · ?
allOf · allOf[133] · ?
allOf · allOf[134] · ?
allOf · allOf[135] · ?
allOf · allOf[136] · ?
allOf · allOf[137] · ?
allOf · allOf[138] · ?
allOf · allOf[139] · ?
allOf · allOf[140] · ?
* event_id · string · $ref ./common-ids.schema.json#/$defs/event_id
Complete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern: ^ak:event:[A-Za-z0-9_-]{44}$
* kind · string
Standard ak.* Event kinds MUST appear in artifacts/registry/event-kind-registry.json. State convergence is defined by the registered pure reducer over kind + payload; producers do not submit typed current result writes.
pattern: ^ak\.[a-z0-9_]+(\.[a-z0-9_]+)*$
realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* scope_ref · $ref #/$defs/scope_ref · $ref #/$defs/scope_ref
Required producer-signed security scope. The closed union is ordinary existing realm, circle, or native sidecar scope plus the create-only realm_genesis exception. It enters proof.event_digest and E2EE AAD. Reducers independently derive the exact scope from schema-validated payload and accepted references; missing dependencies, nonexistent scope, realm_id mismatch, omitted sidecar_id, substituting circle for sidecar, or any unequal field is fail closed. Sidecar domain Event kinds remain Extension-owned; recognizing this native security shape does not make Kernel interpret the Sidecar reducer. Exact product targets remain inside recipient-visible ciphertext.
* actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · …
recursion truncated at depth 8; see source schema for full shape
executed_by · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · …
recursion truncated at depth 8; see source schema for full shape
authorization_ref · oneOf[6]
Optional. Required when executed_by is present. It identifies an accepted Grant, delegation Event, DID-document delegation, or one of the closed profile-specific authority constants. The current governance Station evaluates the reference against the target stream's committed state.
oneOf · oneOf[0] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[2] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[3] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[4] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[5] · …
recursion truncated at depth 8; see source schema for full shape
applet_id · $ref #/$defs/applet_id · $ref #/$defs/applet_id
Optional signed Applet provenance. Required by ak.profile.applet_* when the Event is introduced by an Applet, Ghost Actor, bridge, or delegated applet path. Enters canonical event bytes and therefore is covered by proof.event_digest. When present, authorization_ref MUST also be present and resolve to a real active registration/capability grant binding this applet_id, registration_epoch, action and resource per zh/extensions/applet-integration.md sections 4, 8 and 11. Service-actor self-signature proves provenance but is not an authorization substitute. Capability-gated actions require a grant covering action/resource. For subject_only operations the referenced grant binds only the exact active install and cannot replace the subject signature, FSM or independent action authority. Service self-authored Events use ActorId.service; the install grant subject MUST be the same exact ActorId.service as its producer; hosting Station and effective scope are verified separately without coercing a Service into an account variant.
external_ref · $ref #/$defs/external_ref · $ref #/$defs/external_ref
Optional signed external provenance reference for Applet / bridge-originated Events. It is covered by event_digest and MUST NOT be carried only in unsigned when used for loop prevention, audit, or external-message idempotency. Must not contain unauthorized external plaintext.
* created_at · $ref #/$defs/canonical_event_timestamp · $ref #/$defs/canonical_event_timestamp
semantic_refs · array<$ref #/$defs/semantic_ref>
Optional semantic refs with role. Omit when there are no semantic references; an explicitly empty array is not canonical. Admission selectors determine any required references. PCR policy recovery has no DID-root anchor reference; its policy/session/replacement-key authority is verified separately.
items · …
recursion truncated at depth 8; see source schema for full shape
* payload · object
* producer_proof · $ref #/$defs/event_proof · $ref #/$defs/event_proof
The Event's sole portable producer proof. Storage receipts are separate objects and never authorize this Event. producer_proof and unsigned remain outside the canonical Event digest. Exact retries preserve the verified producer proof.
anyOf · anyOf[3] · object · $ref #/$defs/AccountCursorRevokeOutcome
* revoked · boolean
expires_at · string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
anyOf · anyOf[4] · object · $ref #/$defs/AccountCursorRevokeRequestBody
* cursor · string
pattern: ^ak:cursor:[A-Za-z0-9_-]+$
* reason_code · string
pattern: ^[a-z][a-z0-9_]{0,63}$
revoke_scope · string (enum)
enum: "this_cursor" "same_device" "same_session"
example: "this_cursor"
anyOf · anyOf[5] · object · $ref #/$defs/AccountLogoutOutcome
* revoked · boolean
Whether a live device session was revoked.
anyOf · anyOf[6] · object · $ref #/$defs/AccountLogoutRequestBody
anyOf · anyOf[7] · object · $ref #/$defs/AuthSessionLogoutOutcome
* grant_chain_terminated · boolean
Whether the grant rotation chain is now unable to refresh, including the already-terminated idempotent case.
* auth_session_logged_out · boolean
Whether the underlying Auth-side browser/auth session is now logged out, including the already-logged-out idempotent case.
anyOf · anyOf[8] · object · $ref #/$defs/AuthSessionLogoutRequestBody
Service-to-service Account Authority to Auth Server request that logs out the Auth-side session owning a ak.session.grant rotation chain.
* grant_jwt · string
Session grant used to locate the Auth-side session and its rotation chain.
logout_request_digest · string
Optional digest of the validated client-visible account /logout request that caused this S2S sub-operation.
pattern: ^(sha256|blake3):[0-9a-f]{64}$
validated_at · string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
reason_code · string (enum)
Reason for logging out the Auth-side session. v1 defines only account_logout for this S2S sub-operation.
enum: "account_logout"
anyOf · anyOf[9] · object · $ref #/$defs/AuthzCheckOutcome
ak.self.authz.read.check.v1 diagnostic/preflight decision. See zh/authz/capabilities.md §18. This response is advisory; canonical Event admission remains authoritative.
* decision · string (enum)
`allow` / `hard_deny` are terminal decisions. `soft_deny` is an evaluated policy soft refusal. `quarantine` / `require_review` are local moderation outcomes. Transient dependency or freshness failures are reported through `freshness_state`, `reason_code`, and `retry_after_ms`, not as policy decision values.
enum: "allow" "soft_deny" "hard_deny" "quarantine" "require_review"
matched_grants · array<object>
items · object
applied_constraints · array<object>
items · object
policy_results · array<object>
items · object
missing_proofs · array<object>
items · object
checkpoint · object
freshness_state · string (enum)
Checkpoint freshness classification for revocation-sensitive decisions; see zh/authz/capabilities.md §18.2.
enum: "fresh" "stale" "unknown"
last_known_checkpoint_age_ms · integer
Age of the newest revocation/auth checkpoint evidence used for this decision. Present when freshness_state is stale or unknown.
authority_status · string (enum)
Coarse status of the current governance Station and committed-stream source used to diagnose stale or unknown revocation freshness.
enum: "fresh" "lagging" "unreachable" "unknown"
cache_expires_at · string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
reason_code · string
Registered reason code. High-risk stale or unknown revocation freshness returns revocation_freshness_unknown.
pattern: ^[a-z][a-z0-9_]{0,63}$
retry_after_ms · integer
Set when `freshness_state ∈ {stale,unknown}` or a retryable `reason_code` is present; client SHOULD back off this amount before retry.
obligations · array<object>
Additional local preflight obligations the caller MUST satisfy before the action proceeds.
items · object
anyOf · anyOf[10] · object · $ref #/$defs/AuthzCheckRequestBody
ak.self.authz.read.check.v1 advisory local authorization preflight. It is never a cross-service authorization fact and cannot replace the current governance Station's admission decision.
* actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind · …
recursion truncated at depth 8; see source schema for full shape
* account_id · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* kind · …
recursion truncated at depth 8; see source schema for full shape
* service_id · …
recursion truncated at depth 8; see source schema for full shape
* action · string
Capability action id (e.g. `ak.strand.update`).
resource · object
Optional resource selector (Realm / Strand / Space / Morph / etc.).
context · object
Optional decision context — claim presentations, checkpoint reference, request metadata.
anyOf · anyOf[11] · object · $ref #/$defs/BlobPresignOutcome
* url · string (uri) · format=uri
Fully-qualified URL clients can pass to browser primitives. Contains the `presign` query parameter, `blob_ref`, and a presign envelope bound to `realm_id` for Realm-owned blobs.
pattern: ^https?://
* expires_at · string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
purpose · string
Echo of the issued `purpose`.
anyOf · anyOf[12] · object · $ref #/$defs/BlobPresignRequestBody
* blob_ref · string · $ref ./common-ids.schema.json#/$defs/blob_ref
Content-addressed reference to exact Blob bytes. The embedded suite and digest are the sole wire commitment to those bytes; sibling content/ciphertext digest mirrors are forbidden.
pattern: ^ak:blob:(?:sha256|blake3):[0-9a-f]{64}$
realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
max_age_seconds · integer
Client-requested TTL upper bound. Server clamps to the smaller of this value, the issuing grant's `blob_presign_max_ttl_seconds` constraint, and the deployment-level cap.
purpose · string (enum)
Intended rendering / download mode. Servers MAY apply purpose-specific Content-Disposition or rate limits.
enum: "media_inline" "thumbnail" "download"
anyOf · anyOf[13] · object · $ref #/$defs/CallMediaTokenExchangeOutcome
allOf · allOf[0] · ?
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* call_id · string
pattern: ^ak:call:[A-Za-z0-9_-]{44}$
* actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind · …
recursion truncated at depth 8; see source schema for full shape
* account_id · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* kind · …
recursion truncated at depth 8; see source schema for full shape
* service_id · …
recursion truncated at depth 8; see source schema for full shape
* device_id · string
pattern: ^ak:device:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$
* focus_id · string
pattern: ^(?!ak:)
* connect_url · string (uri) · format=uri
pattern: ^(https|wss)://
* backend_token · ?
Closed branch selected by backend_kind: arkret_native uses the typed signature object; every other v1 backend uses a non-empty opaque string.
* participant_id · string
SFU-local short handle, scope `(call_id, focus_id, sfu_did)`. UUIDv7-form rtc_participant typed ID.
pattern: ^ak:rtc_participant:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$
* participant_binding · object · $ref ./event-payload.schema.json#/$defs/participant_binding
Token issuer's signed commitment over (realm_id, call_id, focus_id, actor_id, device_id, participant_id, expires_at) for a media participant. See crypto-media/media-service-binding.md §3 and crypto-media/call-state.md §4.1. v1 uses the single scheme ak.media.participant_binding.v1.
* expires_at · $ref #/$defs/timestamp · $ref #/$defs/timestamp
* issuer_kid · string
DID URL (with fragment) of the token issuer service signing key. MUST resolve to a service DID present in the current-epoch ak.realm.media_service.service_id.
pattern: ^did:[a-z0-9]+:[^\s?]+#[^\s#?]+$
* sig · $ref #/$defs/non_empty_string · $ref #/$defs/non_empty_string
* expires_at · string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
* backend_kind · string (enum)
Backend binding type identifier (livekit / arkret_native / etc.).
enum: "livekit" "mediasoup" "janus" "arkret_native" "moq_relay"
anyOf · anyOf[14] · object · $ref #/$defs/CallMediaTokenExchangeRequestBody
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* call_id · string
pattern: ^ak:call:[A-Za-z0-9_-]{44}$
* actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind · …
recursion truncated at depth 8; see source schema for full shape
* account_id · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* kind · …
recursion truncated at depth 8; see source schema for full shape
* service_id · …
recursion truncated at depth 8; see source schema for full shape
* device_id · string
Stable protocol endpoint identifier. REQUIRED for agent_key_proof and covered by request_canonical_digest; the Account Authority MUST persist and return the same value in the issued grant so Stations can bind MLS KeyPackage ownership, Welcome routing, consume/revoke operations, refresh, and restart recovery to one endpoint. It MUST NOT be derived from a session or grant id.
pattern: ^ak:device:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$
* focus_id · string
pattern: ^(?!ak:)
capability_refs · array<string>
items · string
pattern: ^ak:grant:[A-Za-z0-9_-]{44}$
desired_media · object
audio · boolean
video · boolean
screen · boolean
anyOf · anyOf[15] · object · $ref #/$defs/DeviceMessagesAckOutcome
* pruned_count · integer
Number of recipient deliveries acknowledged by this token: DeviceMessage rows deleted plus Welcome rows marked delivered and retained for audit; zero is legal for a repeated or older token.
anyOf · anyOf[16] · object · $ref #/$defs/DeviceMessagesAckRequestBody
* ack_token · string
Acknowledgement token previously issued to the same authenticated recipient endpoint by account subscribe or the recipient-delivery list. It cumulatively prunes both DeviceMessage and MlsWelcomeDelivery queue items through the bound position, only after every covered item was durably processed. Unknown / expired / cross-bound tokens MUST be rejected with param_invalid (reason invalid_ack_token) without deleting anything. Naturally idempotent; no Idempotency-Key required.
anyOf · anyOf[17] · object · $ref #/$defs/DeviceMessagesGetOutcome
allOf · allOf[0] · ?
* deliveries · array<$ref ./account-subscribe-frame.schema.json#/$defs/recipient_delivery>
Ordered recipient-private queue items, each discriminated as an unchanged DeviceMessageEnvelope or MlsWelcomeDelivery. These are not shared Event Envelope objects.
items · oneOf[2] · $ref ./account-subscribe-frame.schema.json#/$defs/recipient_delivery
One exact recipient-private queue item. The discriminator selects an unchanged DeviceMessageEnvelope or producer-signed MlsWelcomeDelivery; neither payload is rewritten into the other.
oneOf · oneOf[0] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · …
recursion truncated at depth 8; see source schema for full shape
ack_token · string
Server-issued opaque acknowledgement token, REQUIRED whenever deliveries[] is non-empty. Covers both delivery kinds in this page and earlier items for the authenticated recipient endpoint. Queue deletion happens only through ak.self.device_messages.command.ack.v1 with this token, never through the after= read cursor (client-sync.md §10.1).
next_cursor · string
Read-only continuation position; advancing it MUST NOT delete queued messages.
* has_more · boolean
limited · boolean
lost · boolean
SHOULD be true only for a durably evidenced historical gap or failure since this recipient endpoint's last acknowledged position; normal expiry and capacity MUST NOT delete unacknowledged deliveries of either kind. Clients MUST re-establish MLS/key readiness when true.
anyOf · anyOf[18] · object · $ref #/$defs/DeviceMessagesSendOutcome
* delivered · object
Principal-id to device-id map for messages accepted for delivery.
* unknown_devices · object
Principal-id to device-id map for recipient targets that are not deliverable. Membership alone is the whole result: unknown, revoked, fenced or otherwise undeliverable devices are indistinguishable. A sender-side invalid expires_at never lands here; it fails the whole request.
anyOf · anyOf[19] · object · $ref #/$defs/DeviceMessagesSendRequestBody
* messages · object
Station-local did_core_id -> device_id map. The authenticated addressed Station supplies the AccountId Station component; this body carries no cross-Station route and MUST NOT use ActorId JSON as a key.
anyOf · anyOf[20] · object · $ref #/$defs/DidOperationSubmitOutcome
* status · string (enum)
enum: "accepted" "duplicate" "pending"
* did · string · $ref ./common-ids.schema.json#/$defs/did
Canonical bare DID used for registration, DID method resolution and owner-published current resolution. It contains no path, query or fragment and MUST project through the registered method adapter to exactly one did_core_id.
pattern: ^did:[a-z0-9]+:[^\s/?#]+$
* accepted_at · string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
seq · integer
New method sequence number when available.
* operation_ref · string
Exact method-native immutable operation identifier. For did:webvh this is did + "?versionId=" + the submitted entry versionId. The authenticated response acknowledges the exact complete submitted operation, including proofs; accepted/duplicate MUST match the locally frozen typed request and its method-native version and sequence. A registry MUST NOT normalize or replace accepted entry bytes. A duplicate returns the original result for the same bytes.
receipts · array<object>
items · object
anyOf · anyOf[21] · object · $ref #/$defs/DidOperationSubmitRequestBody
* did · string · $ref ./common-ids.schema.json#/$defs/did
Canonical bare DID used for registration, DID method resolution and owner-published current resolution. It contains no path, query or fragment and MUST project through the registered method adapter to exactly one did_core_id.
pattern: ^did:[a-z0-9]+:[^\s/?#]+$
* did_method · string
DID method discriminator without the did: prefix (e.g. web, webvh, key). It MUST exactly equal the method component of did; verifiers dispatch method-specific validation only after that equality check.
pattern: ^[a-z0-9]+$
seq · integer
Optional method sequence number when the DID method exposes one.
prev_event_digest · string
Optional previous operation hash / key-log head, when required by the DID method.
pattern: ^sha256:[0-9a-f]{64}$
* operation · object
Complete DID method-native operation, including every controller/update/recovery proof required by that method. This is not a generic JSON Patch. The selected adapter MUST validate the immutable native operation and its full history before any state mutation; transport authentication never substitutes for method-native control proof.
anyOf · anyOf[22] · oneOf[2] · $ref #/$defs/DirectConversationFoundingAuthorityEvidence
Closed XOR authorization evidence for one Direct Conversation founding unit, matching the two registered ak.realm.create admission variants. The human branch feeds direct_conversation_genesis; the controller_agent branch feeds direct_conversation_agent_genesis. Carrying both, neither, or mixed branch fields rejects the whole unit.
oneOf · oneOf[0] · object
* kind · const "human"
enum: "human"
* contact_round_evidence · object · $ref ./contact-operations.schema.json#/$defs/contact_round_evidence_bundle
Portable evidence for the pair's current Contact round. The verifier re-derives founder from the root Contact round, never from the current round.
allOf · allOf[0] · …
recursion truncated at depth 8; see source schema for full shape
* contact_round_id · …
recursion truncated at depth 8; see source schema for full shape
previous_terminal_contact_round_id · …
recursion truncated at depth 8; see source schema for full shape
* contact_round · …
recursion truncated at depth 8; see source schema for full shape
* request_receipts · …
recursion truncated at depth 8; see source schema for full shape
normal_response_receipt · …
recursion truncated at depth 8; see source schema for full shape
glare_concurrency_attestations · …
recursion truncated at depth 8; see source schema for full shape
* current_proofs · …
recursion truncated at depth 8; see source schema for full shape
continuity_checkpoint · …
recursion truncated at depth 8; see source schema for full shape
* contact_round_continuity_chains · array<$ref ./contact-operations.schema.json#/$defs/contact_round_evidence_bundle>
Ordered tombstone/recontact predecessors from the current Contact round back to the pair's unique root Contact round, each linked by previous_terminal_contact_round_id. An empty array means the current round is itself the root. A break, a cycle, multiple roots or two directional proofs yielding different roots reject the unit.
items · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* kind · const "controller_agent"
enum: "controller_agent"
* agent_provision_ref · string · $ref ./principal-operations.schema.json#/$defs/event_id
Complete identity of the accepted Agent provision Event. Its digest is derived by decoding this suite-tagged full-digest EventId; no parallel agent_provision_digest is carried.
pattern: ^ak:event:[A-Za-z0-9_-]{44}$
* controller_binding_digest · string · $ref ./principal-operations.schema.json#/$defs/digest
pattern: ^sha256:[0-9a-f]{64}$
anyOf · anyOf[23] · object · $ref #/$defs/EventAdmissionSubmission
One exact producer-signed Event submitted to the current governance Station, plus the approval signatures required by a grant, Realm governance or List WIP policy for the Event action or for this registered submit operation. There are no RealmCommit, typed current result, offline-lease or proof-bundle sidecars. approval_signatures is the only sidecar and it is deliberately outside event: the Event bytes and event_id are finished before any approval is signed, so attaching them never changes the Event (zh/authz/constraint-schema.md section 9.2.5).
* event · object · $ref ./event-envelope.schema.json
Closed producer-signed Event. Shared persistent Events become final only when the current Realm governance Station issues a RealmCommit in the derived Realm, Circle, or Sidecar stream.
allOf · allOf[0] · ?
allOf · allOf[1] · ?
allOf · allOf[2] · ?
allOf · allOf[3] · ?
allOf · allOf[4] · ?
allOf · allOf[5] · $ref #/$defs/registered_admission_shape · $ref #/$defs/registered_admission_shape
allOf · allOf[6] · $ref #/$defs/registered_execution_shape · $ref #/$defs/registered_execution_shape
allOf · allOf[7] · ?
allOf · allOf[8] · ?
allOf · allOf[9] · ?
allOf · allOf[10] · ?
allOf · allOf[11] · ?
allOf · allOf[12] · ?
allOf · allOf[13] · ?
allOf · allOf[14] · ?
allOf · allOf[15] · ?
allOf · allOf[16] · ?
allOf · allOf[17] · ?
allOf · allOf[18] · ?
allOf · allOf[19] · ?
allOf · allOf[20] · ?
allOf · allOf[21] · ?
allOf · allOf[22] · ?
allOf · allOf[23] · ?
allOf · allOf[24] · ?
allOf · allOf[25] · ?
allOf · allOf[26] · ?
allOf · allOf[27] · ?
allOf · allOf[28] · ?
allOf · allOf[29] · ?
allOf · allOf[30] · ?
allOf · allOf[31] · ?
allOf · allOf[32] · ?
allOf · allOf[33] · ?
allOf · allOf[34] · ?
allOf · allOf[35] · ?
allOf · allOf[36] · ?
allOf · allOf[37] · ?
allOf · allOf[38] · ?
allOf · allOf[39] · ?
allOf · allOf[40] · ?
allOf · allOf[41] · ?
allOf · allOf[42] · ?
allOf · allOf[43] · ?
allOf · allOf[44] · ?
allOf · allOf[45] · ?
allOf · allOf[46] · ?
allOf · allOf[47] · ?
allOf · allOf[48] · ?
allOf · allOf[49] · ?
allOf · allOf[50] · ?
allOf · allOf[51] · ?
allOf · allOf[52] · ?
allOf · allOf[53] · ?
allOf · allOf[54] · ?
allOf · allOf[55] · ?
allOf · allOf[56] · ?
allOf · allOf[57] · ?
allOf · allOf[58] · ?
allOf · allOf[59] · ?
allOf · allOf[60] · ?
allOf · allOf[61] · ?
allOf · allOf[62] · ?
allOf · allOf[63] · ?
allOf · allOf[64] · ?
allOf · allOf[65] · ?
allOf · allOf[66] · ?
allOf · allOf[67] · ?
allOf · allOf[68] · ?
allOf · allOf[69] · ?
allOf · allOf[70] · ?
allOf · allOf[71] · ?
allOf · allOf[72] · ?
allOf · allOf[73] · ?
allOf · allOf[74] · ?
allOf · allOf[75] · ?
allOf · allOf[76] · ?
allOf · allOf[77] · ?
allOf · allOf[78] · ?
allOf · allOf[79] · ?
allOf · allOf[80] · ?
allOf · allOf[81] · ?
allOf · allOf[82] · ?
allOf · allOf[83] · ?
allOf · allOf[84] · ?
allOf · allOf[85] · ?
allOf · allOf[86] · ?
allOf · allOf[87] · ?
allOf · allOf[88] · ?
allOf · allOf[89] · ?
allOf · allOf[90] · ?
allOf · allOf[91] · ?
allOf · allOf[92] · ?
allOf · allOf[93] · ?
allOf · allOf[94] · ?
allOf · allOf[95] · ?
allOf · allOf[96] · ?
allOf · allOf[97] · ?
allOf · allOf[98] · ?
allOf · allOf[99] · ?
allOf · allOf[100] · ?
allOf · allOf[101] · ?
allOf · allOf[102] · ?
allOf · allOf[103] · ?
allOf · allOf[104] · ?
allOf · allOf[105] · ?
allOf · allOf[106] · ?
allOf · allOf[107] · ?
allOf · allOf[108] · ?
allOf · allOf[109] · ?
allOf · allOf[110] · ?
allOf · allOf[111] · ?
allOf · allOf[112] · ?
allOf · allOf[113] · ?
allOf · allOf[114] · ?
allOf · allOf[115] · ?
allOf · allOf[116] · ?
allOf · allOf[117] · ?
allOf · allOf[118] · ?
allOf · allOf[119] · ?
allOf · allOf[120] · ?
allOf · allOf[121] · ?
allOf · allOf[122] · ?
allOf · allOf[123] · ?
allOf · allOf[124] · ?
allOf · allOf[125] · ?
allOf · allOf[126] · ?
allOf · allOf[127] · ?
allOf · allOf[128] · ?
allOf · allOf[129] · ?
allOf · allOf[130] · ?
allOf · allOf[131] · ?
allOf · allOf[132] · ?
allOf · allOf[133] · ?
allOf · allOf[134] · ?
allOf · allOf[135] · ?
allOf · allOf[136] · ?
allOf · allOf[137] · ?
allOf · allOf[138] · ?
allOf · allOf[139] · ?
allOf · allOf[140] · ?
* event_id · string · $ref ./common-ids.schema.json#/$defs/event_id
Complete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern: ^ak:event:[A-Za-z0-9_-]{44}$
* kind · string
Standard ak.* Event kinds MUST appear in artifacts/registry/event-kind-registry.json. State convergence is defined by the registered pure reducer over kind + payload; producers do not submit typed current result writes.
pattern: ^ak\.[a-z0-9_]+(\.[a-z0-9_]+)*$
realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* scope_ref · $ref #/$defs/scope_ref · $ref #/$defs/scope_ref
Required producer-signed security scope. The closed union is ordinary existing realm, circle, or native sidecar scope plus the create-only realm_genesis exception. It enters proof.event_digest and E2EE AAD. Reducers independently derive the exact scope from schema-validated payload and accepted references; missing dependencies, nonexistent scope, realm_id mismatch, omitted sidecar_id, substituting circle for sidecar, or any unequal field is fail closed. Sidecar domain Event kinds remain Extension-owned; recognizing this native security shape does not make Kernel interpret the Sidecar reducer. Exact product targets remain inside recipient-visible ciphertext.
* actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · …
recursion truncated at depth 8; see source schema for full shape
executed_by · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · …
recursion truncated at depth 8; see source schema for full shape
authorization_ref · oneOf[6]
Optional. Required when executed_by is present. It identifies an accepted Grant, delegation Event, DID-document delegation, or one of the closed profile-specific authority constants. The current governance Station evaluates the reference against the target stream's committed state.
oneOf · oneOf[0] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[2] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[3] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[4] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[5] · …
recursion truncated at depth 8; see source schema for full shape
applet_id · $ref #/$defs/applet_id · $ref #/$defs/applet_id
Optional signed Applet provenance. Required by ak.profile.applet_* when the Event is introduced by an Applet, Ghost Actor, bridge, or delegated applet path. Enters canonical event bytes and therefore is covered by proof.event_digest. When present, authorization_ref MUST also be present and resolve to a real active registration/capability grant binding this applet_id, registration_epoch, action and resource per zh/extensions/applet-integration.md sections 4, 8 and 11. Service-actor self-signature proves provenance but is not an authorization substitute. Capability-gated actions require a grant covering action/resource. For subject_only operations the referenced grant binds only the exact active install and cannot replace the subject signature, FSM or independent action authority. Service self-authored Events use ActorId.service; the install grant subject MUST be the same exact ActorId.service as its producer; hosting Station and effective scope are verified separately without coercing a Service into an account variant.
external_ref · $ref #/$defs/external_ref · $ref #/$defs/external_ref
Optional signed external provenance reference for Applet / bridge-originated Events. It is covered by event_digest and MUST NOT be carried only in unsigned when used for loop prevention, audit, or external-message idempotency. Must not contain unauthorized external plaintext.
* created_at · $ref #/$defs/canonical_event_timestamp · $ref #/$defs/canonical_event_timestamp
semantic_refs · array<$ref #/$defs/semantic_ref>
Optional semantic refs with role. Omit when there are no semantic references; an explicitly empty array is not canonical. Admission selectors determine any required references. PCR policy recovery has no DID-root anchor reference; its policy/session/replacement-key authority is verified separately.
items · …
recursion truncated at depth 8; see source schema for full shape
* payload · object
* producer_proof · $ref #/$defs/event_proof · $ref #/$defs/event_proof
The Event's sole portable producer proof. Storage receipts are separate objects and never authorize this Event. producer_proof and unsigned remain outside the canonical Event digest. Exact retries preserve the verified producer proof.
approval_signatures · array<$ref ./approval-signature.schema.json>
One ak.schema.approval_signature.v1 object per approver. An event-target signature binds approval_target.event_id equal to event.event_id. An operation-target signature is allowed only when capability-action-registry.json resolves its action to this exact carrier operation and binds request_canonical_digest to the original typed request with approval_signatures omitted. Every ingress that wraps EventAdmissionSubmission -- ordinary self submit, batch submission, control transactions, facade hand-off -- reuses this one field and MUST NOT define its own DTO. The array is omitted when no approval layer demands evidence; it MUST NOT be present and empty. The governance Station persists the evidence, the verification basis, the nonce consumption and the binding to this submission inside the same atomic acceptance transaction, and the shared Realm Event store keeps the original Event bytes unchanged.
items · object · $ref ./approval-signature.schema.json
The single approval evidence type of v1 (zh/authz/constraint-schema.md section 9.2). One approver signs one exact target: either a fully authored Event that has not been submitted yet, or the original typed RequestBody of one operation whose evidence carrier is registered in capability-action-registry.json. The object is not an Event, never enters Realm history, and MUST NOT be written into an EventEnvelope, a signed payload or an Event semantic_refs[] entry. It travels in the carrier registered for the approved action. It proves that an approver approved that target; it proves nothing about the initiator's own authority.
* input · …
recursion truncated at depth 8; see source schema for full shape
* proof · …
recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[24] · object · $ref #/$defs/EventDeliveryStatusOutcome
Complete frozen target set for one visible Event. Rows are sorted byte-wise by unique opaque target_id. Consumers derive the pending count by counting pending_route and pending_delivery rows, and derive aggregate state as pending iff that count is non-zero.
* event_id · string · $ref #/$defs/EventId
pattern: ^ak:event:[A-Za-z0-9_-]{44}$
* targets · array<$ref #/$defs/EventDeliveryTargetStatus>
items · object · $ref #/$defs/EventDeliveryTargetStatus
Authorized projection of one frozen Realm fanout target. target_id is opaque and stable. service_id is present only when the caller can currently read at least one exact joined-member ActorId that contributed the target.
* target_id · …
recursion truncated at depth 8; see source schema for full shape
* status · …
recursion truncated at depth 8; see source schema for full shape
service_id · …
recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[25] · object · $ref #/$defs/EventDeliveryStatusRequestBody
Authenticated, non-enumerating request for the durable fanout state of one caller-visible accepted Event.
* event_id · string · $ref #/$defs/EventId
pattern: ^ak:event:[A-Za-z0-9_-]{44}$
anyOf · anyOf[26] · object · $ref #/$defs/EventSubmitEnvelope
Closed producer-signed Event. Shared persistent Events become final only when the current Realm governance Station issues a RealmCommit in the derived Realm, Circle, or Sidecar stream.
allOf · allOf[0] · ?
allOf · allOf[1] · ?
allOf · allOf[2] · ?
allOf · allOf[3] · ?
allOf · allOf[4] · ?
allOf · allOf[5] · $ref #/$defs/registered_admission_shape · $ref #/$defs/registered_admission_shape
allOf · allOf[6] · $ref #/$defs/registered_execution_shape · $ref #/$defs/registered_execution_shape
allOf · allOf[7] · ?
allOf · allOf[8] · ?
allOf · allOf[9] · ?
allOf · allOf[10] · ?
allOf · allOf[11] · ?
allOf · allOf[12] · ?
allOf · allOf[13] · ?
allOf · allOf[14] · ?
allOf · allOf[15] · ?
allOf · allOf[16] · ?
allOf · allOf[17] · ?
allOf · allOf[18] · ?
allOf · allOf[19] · ?
allOf · allOf[20] · ?
allOf · allOf[21] · ?
allOf · allOf[22] · ?
allOf · allOf[23] · ?
allOf · allOf[24] · ?
allOf · allOf[25] · ?
allOf · allOf[26] · ?
allOf · allOf[27] · ?
allOf · allOf[28] · ?
allOf · allOf[29] · ?
allOf · allOf[30] · ?
allOf · allOf[31] · ?
allOf · allOf[32] · ?
allOf · allOf[33] · ?
allOf · allOf[34] · ?
allOf · allOf[35] · ?
allOf · allOf[36] · ?
allOf · allOf[37] · ?
allOf · allOf[38] · ?
allOf · allOf[39] · ?
allOf · allOf[40] · ?
allOf · allOf[41] · ?
allOf · allOf[42] · ?
allOf · allOf[43] · ?
allOf · allOf[44] · ?
allOf · allOf[45] · ?
allOf · allOf[46] · ?
allOf · allOf[47] · ?
allOf · allOf[48] · ?
allOf · allOf[49] · ?
allOf · allOf[50] · ?
allOf · allOf[51] · ?
allOf · allOf[52] · ?
allOf · allOf[53] · ?
allOf · allOf[54] · ?
allOf · allOf[55] · ?
allOf · allOf[56] · ?
allOf · allOf[57] · ?
allOf · allOf[58] · ?
allOf · allOf[59] · ?
allOf · allOf[60] · ?
allOf · allOf[61] · ?
allOf · allOf[62] · ?
allOf · allOf[63] · ?
allOf · allOf[64] · ?
allOf · allOf[65] · ?
allOf · allOf[66] · ?
allOf · allOf[67] · ?
allOf · allOf[68] · ?
allOf · allOf[69] · ?
allOf · allOf[70] · ?
allOf · allOf[71] · ?
allOf · allOf[72] · ?
allOf · allOf[73] · ?
allOf · allOf[74] · ?
allOf · allOf[75] · ?
allOf · allOf[76] · ?
allOf · allOf[77] · ?
allOf · allOf[78] · ?
allOf · allOf[79] · ?
allOf · allOf[80] · ?
allOf · allOf[81] · ?
allOf · allOf[82] · ?
allOf · allOf[83] · ?
allOf · allOf[84] · ?
allOf · allOf[85] · ?
allOf · allOf[86] · ?
allOf · allOf[87] · ?
allOf · allOf[88] · ?
allOf · allOf[89] · ?
allOf · allOf[90] · ?
allOf · allOf[91] · ?
allOf · allOf[92] · ?
allOf · allOf[93] · ?
allOf · allOf[94] · ?
allOf · allOf[95] · ?
allOf · allOf[96] · ?
allOf · allOf[97] · ?
allOf · allOf[98] · ?
allOf · allOf[99] · ?
allOf · allOf[100] · ?
allOf · allOf[101] · ?
allOf · allOf[102] · ?
allOf · allOf[103] · ?
allOf · allOf[104] · ?
allOf · allOf[105] · ?
allOf · allOf[106] · ?
allOf · allOf[107] · ?
allOf · allOf[108] · ?
allOf · allOf[109] · ?
allOf · allOf[110] · ?
allOf · allOf[111] · ?
allOf · allOf[112] · ?
allOf · allOf[113] · ?
allOf · allOf[114] · ?
allOf · allOf[115] · ?
allOf · allOf[116] · ?
allOf · allOf[117] · ?
allOf · allOf[118] · ?
allOf · allOf[119] · ?
allOf · allOf[120] · ?
allOf · allOf[121] · ?
allOf · allOf[122] · ?
allOf · allOf[123] · ?
allOf · allOf[124] · ?
allOf · allOf[125] · ?
allOf · allOf[126] · ?
allOf · allOf[127] · ?
allOf · allOf[128] · ?
allOf · allOf[129] · ?
allOf · allOf[130] · ?
allOf · allOf[131] · ?
allOf · allOf[132] · ?
allOf · allOf[133] · ?
allOf · allOf[134] · ?
allOf · allOf[135] · ?
allOf · allOf[136] · ?
allOf · allOf[137] · ?
allOf · allOf[138] · ?
allOf · allOf[139] · ?
allOf · allOf[140] · ?
* event_id · string · $ref ./common-ids.schema.json#/$defs/event_id
Complete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern: ^ak:event:[A-Za-z0-9_-]{44}$
* kind · string
Standard ak.* Event kinds MUST appear in artifacts/registry/event-kind-registry.json. State convergence is defined by the registered pure reducer over kind + payload; producers do not submit typed current result writes.
pattern: ^ak\.[a-z0-9_]+(\.[a-z0-9_]+)*$
realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* scope_ref · $ref #/$defs/scope_ref · $ref #/$defs/scope_ref
Required producer-signed security scope. The closed union is ordinary existing realm, circle, or native sidecar scope plus the create-only realm_genesis exception. It enters proof.event_digest and E2EE AAD. Reducers independently derive the exact scope from schema-validated payload and accepted references; missing dependencies, nonexistent scope, realm_id mismatch, omitted sidecar_id, substituting circle for sidecar, or any unequal field is fail closed. Sidecar domain Event kinds remain Extension-owned; recognizing this native security shape does not make Kernel interpret the Sidecar reducer. Exact product targets remain inside recipient-visible ciphertext.
* actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind · …
recursion truncated at depth 8; see source schema for full shape
* account_id · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* kind · …
recursion truncated at depth 8; see source schema for full shape
* service_id · …
recursion truncated at depth 8; see source schema for full shape
executed_by · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind · …
recursion truncated at depth 8; see source schema for full shape
* account_id · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* kind · …
recursion truncated at depth 8; see source schema for full shape
* service_id · …
recursion truncated at depth 8; see source schema for full shape
authorization_ref · oneOf[6]
Optional. Required when executed_by is present. It identifies an accepted Grant, delegation Event, DID-document delegation, or one of the closed profile-specific authority constants. The current governance Station evaluates the reference against the target stream's committed state.
oneOf · oneOf[0] · $ref #/$defs/grant_ref · $ref #/$defs/grant_ref
oneOf · oneOf[1] · $ref #/$defs/event_ref · $ref #/$defs/event_ref
oneOf · oneOf[2] · $ref #/$defs/did_delegation_ref · $ref #/$defs/did_delegation_ref
oneOf · oneOf[3] · $ref #/$defs/direct_conversation_participant_authority_ref · $ref #/$defs/direct_conversation_participant_authority_ref
oneOf · oneOf[4] · $ref #/$defs/direct_conversation_bootstrap_authority_ref · $ref #/$defs/direct_conversation_bootstrap_authority_ref
oneOf · oneOf[5] · $ref #/$defs/membership_compensation_delegation_ref · $ref #/$defs/membership_compensation_delegation_ref
applet_id · $ref #/$defs/applet_id · $ref #/$defs/applet_id
Optional signed Applet provenance. Required by ak.profile.applet_* when the Event is introduced by an Applet, Ghost Actor, bridge, or delegated applet path. Enters canonical event bytes and therefore is covered by proof.event_digest. When present, authorization_ref MUST also be present and resolve to a real active registration/capability grant binding this applet_id, registration_epoch, action and resource per zh/extensions/applet-integration.md sections 4, 8 and 11. Service-actor self-signature proves provenance but is not an authorization substitute. Capability-gated actions require a grant covering action/resource. For subject_only operations the referenced grant binds only the exact active install and cannot replace the subject signature, FSM or independent action authority. Service self-authored Events use ActorId.service; the install grant subject MUST be the same exact ActorId.service as its producer; hosting Station and effective scope are verified separately without coercing a Service into an account variant.
external_ref · $ref #/$defs/external_ref · $ref #/$defs/external_ref
Optional signed external provenance reference for Applet / bridge-originated Events. It is covered by event_digest and MUST NOT be carried only in unsigned when used for loop prevention, audit, or external-message idempotency. Must not contain unauthorized external plaintext.
* created_at · $ref #/$defs/canonical_event_timestamp · $ref #/$defs/canonical_event_timestamp
semantic_refs · array<$ref #/$defs/semantic_ref>
Optional semantic refs with role. Omit when there are no semantic references; an explicitly empty array is not canonical. Admission selectors determine any required references. PCR policy recovery has no DID-root anchor reference; its policy/session/replacement-key authority is verified separately.
items · $ref #/$defs/semantic_ref · $ref #/$defs/semantic_ref
* payload · object
* producer_proof · $ref #/$defs/event_proof · $ref #/$defs/event_proof
The Event's sole portable producer proof. Storage receipts are separate objects and never authorize this Event. producer_proof and unsigned remain outside the canonical Event digest. Exact retries preserve the verified producer proof.
anyOf · anyOf[27] · object · $ref #/$defs/EventsSubmitBatchRequestBody
Legacy-named typed array retained only as the nested prepared_event_unit request in security-transaction.schema.json. It is not an ak.self.events.command.submit.v1 request: that operation accepts only authority-commit-operations.schema.json#/$defs/self_submit_request, including its closed ordinary_realm_bootstrap branch. The parent security transaction fixes the recovery unit type, slot count, order and authorization; this array alone grants no generic Event batch admission.
* events · array<$ref #/$defs/EventAdmissionSubmission>
items · object · $ref #/$defs/EventAdmissionSubmission
One exact producer-signed Event submitted to the current governance Station, plus the approval signatures required by a grant, Realm governance or List WIP policy for the Event action or for this registered submit operation. There are no RealmCommit, typed current result, offline-lease or proof-bundle sidecars. approval_signatures is the only sidecar and it is deliberately outside event: the Event bytes and event_id are finished before any approval is signed, so attaching them never changes the Event (zh/authz/constraint-schema.md section 9.2.5).
* event · …
recursion truncated at depth 8; see source schema for full shape
approval_signatures · …
recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[28] · object · $ref #/$defs/GrantList
Atomic subject-visible snapshot of active effective grants. Each row carries its own exact current-result revision; state_digest authenticates the list as a whole and is never a per-grant CAS operand.
* grants · array<$ref #/$defs/EffectiveCapabilityGrantRow>
items · object · $ref #/$defs/EffectiveCapabilityGrantRow
One active effective capability grant and the exact revision of that same capability_grant current result, read atomically by the governing Station. This revision is the only valid authoring basis for a subject-signed ak.capability.relinquish Event; state_digest, evaluated_at, Event ids and locally folded history MUST NOT substitute for it.
* grant · …
recursion truncated at depth 8; see source schema for full shape
* revision · …
recursion truncated at depth 8; see source schema for full shape
* state_digest · string
Digest of the complete effective-list snapshot. It MUST NOT be copied into expected_revision or otherwise treated as one grant's revision.
pattern: ^(sha256|blake3):[0-9a-f]{64}$
* evaluated_at · string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
anyOf · anyOf[29] · object · $ref #/$defs/IdentityDocumentView
Result of ak.root.identity.document.resource.get.v1 — current DID Document plus normalized view hints.
* did_document · object
Raw DID Core document with W3C field names preserved.
normalized_view · object
Optional Arkret normalized principal view (snake_case) — derived projection only, NOT a re-publishable DID Document. See zh/identity/identity-did.md §6.
method_evidence · oneOf[3] · $ref ./identity-resolution.schema.json#/$defs/method_history_evidence
Adapter-routed evidence. evidence_kind is the single-source discriminator: the receiver resolves it through did-method-adapter-registry.json method_evidence_kind, which is unique across active adapters, to exactly one active adapter for this versioned schema. The evidence carries no adapter_version; an adapter change requires a new schema/operation version rather than a registry drift under the same wire shape. Unknown evidence kinds fail closed.
oneOf · oneOf[0] · $ref #/$defs/webvh_method_history_evidence · $ref #/$defs/webvh_method_history_evidence
oneOf · oneOf[1] · $ref #/$defs/did_web_method_history_evidence · $ref #/$defs/did_web_method_history_evidence
oneOf · oneOf[2] · $ref #/$defs/did_key_method_history_evidence · $ref #/$defs/did_key_method_history_evidence
cached_at · string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
anyOf · anyOf[30] · object · $ref #/$defs/IdentityLogListOutcome
Result of ak.root.identity.log.read.list.v1. Entries are returned in the DID method's own native log form: for did:webvh each entry is a verbatim did.jsonl log entry with its native versionId, entryHash chain and Data Integrity proof. Arkret defines no parallel entry envelope, sequence numbering, hash chain or proof transcript over DID logs — the method already provides all of them, and a second signed representation of the same history could disagree with the first. Methods without a native history (did:web) MUST report that rather than being wrapped in a shape that implies one.
* did · string · $ref ./common-ids.schema.json#/$defs/did
Canonical bare DID used for registration, DID method resolution and owner-published current resolution. It contains no path, query or fragment and MUST project through the registered method adapter to exactly one did_core_id.
pattern: ^did:[a-z0-9]+:[^\s/?#]+$
* method · string
DID method of the returned log, e.g. did:webvh. Consumers dispatch parsing and verification on this value.
native_history · boolean
False when the method has no native key history at all (did:web). Such a response MUST return an empty entries array; the server MUST NOT synthesise entries, sequence numbers or a chain the method does not have.
* entries · array<object>
Verbatim method-native log entries in method order. Arkret does not reinterpret, renumber or re-sign them; verification follows the method specification.
items · object
next_cursor · string
Opaque continuation cursor for the next page when has_more=true.
* has_more · boolean
anyOf · anyOf[31] · object · $ref #/$defs/IdentityReceiptListOutcome
Result of ak.root.identity.receipts.read.list.v1. receipts[] is a tagged union over two distinct object families discriminated by their schema constant: ak.schema.identity_receipt.v1 records a role inside a DID registry consensus group (writer / witness / replica) and binds seq + accepted_entry_digest, while ak.schema.did_webvh_witness_receipt.v1 records a did:webvh method witness observed at a specific versionId. The two say different things with the same English word, so the discriminator is mandatory and a verifier MUST branch on it rather than infer intent from which optional fields happen to be present.
* receipts · array<oneOf[2]>
items · oneOf[2]
oneOf · oneOf[0] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · …
recursion truncated at depth 8; see source schema for full shape
threshold_met · boolean
True when the returned receipt set satisfies the effective witness threshold for the requested head. The effective threshold is the strictest intersection of the method-native parameters.witness.threshold and the deployment / Realm policy minimum (identity-did.md §3.4.2), and distinctness is counted over controlling_organization_did where policy requires distinct organizations. Omitted when the registry cannot evaluate threshold policy for this query; an omitted value MUST NOT be read as true. A true value is an Arkret-layer convenience and MUST NOT replace verifying the standard did-witness.json proofs.
anyOf · anyOf[32] · object · $ref #/$defs/IdentityResolveOutcome
did_document · object
key_log_head · string · $ref ./account-operations.schema.json#/$defs/digest
pattern: ^(sha256|blake3):[0-9a-f]{64}$
seq · integer
method_evidence · oneOf[1] · $ref #/$defs/IdentityMethodEvidence
oneOf · oneOf[0] · object · $ref #/$defs/DidWebvhIdentityMethodEvidence
Method-native pins derived only after fail-closed verification of the complete did:webvh history. control_key_digest is SHA-256 over the decoded canonical multikey bytes of parameters.updateKeys[0] at version_id.
* kind · …
recursion truncated at depth 8; see source schema for full shape
* version_id · …
recursion truncated at depth 8; see source schema for full shape
* control_key_digest · …
recursion truncated at depth 8; see source schema for full shape
receipts · array<$ref ./identity-receipt.schema.json>
items · object · $ref ./identity-receipt.schema.json
* schema · …
recursion truncated at depth 8; see source schema for full shape
* receipt_id · …
recursion truncated at depth 8; see source schema for full shape
* subject_did · …
recursion truncated at depth 8; see source schema for full shape
* seq · …
recursion truncated at depth 8; see source schema for full shape
* accepted_entry_digest · …
recursion truncated at depth 8; see source schema for full shape
* registry_id · …
recursion truncated at depth 8; see source schema for full shape
* witness_role · …
recursion truncated at depth 8; see source schema for full shape
audience · …
recursion truncated at depth 8; see source schema for full shape
* created_at · …
recursion truncated at depth 8; see source schema for full shape
* signature · …
recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[33] · object · $ref #/$defs/IdentityResolveRequestBody
* did · string · $ref ./common-ids.schema.json#/$defs/did
Canonical bare DID used for registration, DID method resolution and owner-published current resolution. It contains no path, query or fragment and MUST project through the registered method adapter to exactly one did_core_id.
pattern: ^did:[a-z0-9]+:[^\s/?#]+$
requested_evidence_kinds · array<string (enum)>
items · string (enum)
enum: "did_webvh"
anyOf · anyOf[34] · object · $ref #/$defs/InitialSessionGrantIntent
Initial Standard SessionGrant intent embedded in identity_creation registration. It reuses the DPoP holder key established by account handoff; Account Authority recomputes RFC 7638 thumbprint of session_public_key and requires equality with the handoff/control-proof dpop_jkt. It is not a separate authorization or credential.
* device_id · string · $ref ./common-ids.schema.json#/$defs/device_id
pattern: ^ak:device:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$
* session_public_key · string (canonical-public-jwk-jcs) · format=canonical-public-jwk-jcs
Exact RFC 8785 JCS public JWK for the existing handoff DPoP holder key. Private members are forbidden.
* audience_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
anyOf · anyOf[35] · object · $ref #/$defs/MlsGroupStateMaterialOutcome
Exact RFC 9420 public group-state material. *_bytes_b64 use unpadded base64url. Consumers MUST decode each content-addressed Blob ref's embedded suite, hash the raw bytes under that suite, compare the digest, verify GroupInfo and ratchet_tree consistency, then derive leaf_index only from occupied leaves in the verified tree. Blob suites are independent of the fixed SHA-256 Event/RealmCommit identity suite.
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* effective_scope · oneOf[3] · $ref ./event-payload.schema.json#/$defs/effective_scope
oneOf · oneOf[0] · object
* kind · …
recursion truncated at depth 8; see source schema for full shape
* realm_id · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* kind · …
recursion truncated at depth 8; see source schema for full shape
* realm_id · …
recursion truncated at depth 8; see source schema for full shape
* circle_id · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[2] · object
* kind · …
recursion truncated at depth 8; see source schema for full shape
* realm_id · …
recursion truncated at depth 8; see source schema for full shape
* sidecar_id · …
recursion truncated at depth 8; see source schema for full shape
* mls_group_id · string · $ref ./common-ids.schema.json#/$defs/mls_group_id
RFC 9420 group_id as base64url_no_pad(SHA-256(UTF8("ak.mls.group_id.v1") || 0x00 || canonical_effective_scope_key_bytes(effective_scope))), so exactly 43 characters. Derived by the reducer and the SDK from the effective scope alone; actors never submit it. The v1 formula is the only one: the earlier reversible base64url of the scope key bytes MUST NOT be accepted alongside it. See zh/models/realm-and-space.md section 2.2.
pattern: ^[A-Za-z0-9_-]{43}$
* epoch · const 0
enum: 0
* group_state_event_id · string · $ref #/$defs/EventId
pattern: ^ak:event:[A-Za-z0-9_-]{44}$
* group_info_ref · string
Copied byte-for-byte from the accepted ak.mls.genesis payload; the embedded Blob digest suite is the sole wire carrier of the material digest and is independent of the fixed SHA-256 Event/RealmCommit identity suite (encoding.md 4.0.1).
pattern: ^ak:blob:(?:sha256|blake3):[0-9a-f]{64}$
* group_info_bytes_b64 · string
pattern: ^[A-Za-z0-9_-]+$
* ratchet_tree_ref · string
Copied byte-for-byte from the accepted ak.mls.genesis payload; the embedded Blob digest suite is the sole wire carrier of the material digest and is independent of the fixed SHA-256 Event/RealmCommit identity suite (encoding.md 4.0.1).
pattern: ^ak:blob:(?:sha256|blake3):[0-9a-f]{64}$
* ratchet_tree_bytes_b64 · string
pattern: ^[A-Za-z0-9_-]+$
anyOf · anyOf[36] · object · $ref #/$defs/MlsGroupStateMaterialRequestBody
Read-only service request for the exact public MLS epoch-0 GroupInfo and ratchet_tree bytes committed by one accepted ak.mls.genesis Event. Every Genesis selector is copied from that Event. When caller_actor_id is present, target_commit_event_ref and target_epoch are mandatory; governance checks current and target-cut member/history authority and source Station replication right at the target accepted Commit cut. Without caller_actor_id this remains the original Station replication-only read, with source Station replication right checked at the Genesis Commit position.
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* effective_scope · oneOf[3] · $ref ./event-payload.schema.json#/$defs/effective_scope
oneOf · oneOf[0] · object
* kind · …
recursion truncated at depth 8; see source schema for full shape
* realm_id · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* kind · …
recursion truncated at depth 8; see source schema for full shape
* realm_id · …
recursion truncated at depth 8; see source schema for full shape
* circle_id · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[2] · object
* kind · …
recursion truncated at depth 8; see source schema for full shape
* realm_id · …
recursion truncated at depth 8; see source schema for full shape
* sidecar_id · …
recursion truncated at depth 8; see source schema for full shape
* mls_group_id · string · $ref ./common-ids.schema.json#/$defs/mls_group_id
RFC 9420 group_id as base64url_no_pad(SHA-256(UTF8("ak.mls.group_id.v1") || 0x00 || canonical_effective_scope_key_bytes(effective_scope))), so exactly 43 characters. Derived by the reducer and the SDK from the effective scope alone; actors never submit it. The v1 formula is the only one: the earlier reversible base64url of the scope key bytes MUST NOT be accepted alongside it. See zh/models/realm-and-space.md section 2.2.
pattern: ^[A-Za-z0-9_-]{43}$
* epoch · const 0
enum: 0
* group_state_event_id · string · $ref #/$defs/EventId
pattern: ^ak:event:[A-Za-z0-9_-]{44}$
caller_actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind · …
recursion truncated at depth 8; see source schema for full shape
* account_id · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* kind · …
recursion truncated at depth 8; see source schema for full shape
* service_id · …
recursion truncated at depth 8; see source schema for full shape
target_commit_event_ref · string · $ref #/$defs/EventId
pattern: ^ak:event:[A-Za-z0-9_-]{44}$
target_epoch · integer
* group_info_ref · string
Copied byte-for-byte from the accepted ak.mls.genesis payload; the embedded Blob digest suite is the sole wire carrier of the material digest and is independent of the fixed SHA-256 Event/RealmCommit identity suite (encoding.md 4.0.1).
pattern: ^ak:blob:(?:sha256|blake3):[0-9a-f]{64}$
* ratchet_tree_ref · string
Copied byte-for-byte from the accepted ak.mls.genesis payload; the embedded Blob digest suite is the sole wire carrier of the material digest and is independent of the fixed SHA-256 Event/RealmCommit identity suite (encoding.md 4.0.1).
pattern: ^ak:blob:(?:sha256|blake3):[0-9a-f]{64}$
max_response_bytes · integer
example: 8388608
anyOf · anyOf[37] · object · $ref #/$defs/ModerationReportOutcome
* report_id · string
pattern: ^ak:report:[A-Za-z0-9_-]{44}$
routed_to_ids · array<$ref ./common-ids.schema.json#/$defs/did_core_id>
Stable core_ids selected as moderation routing destinations. MUST be omitted for an ordinary reporter and MAY be serialized only when the caller independently holds moderation/governance capability for the report's exact scope. Endpoint discovery and DID verification remain separate resolution steps.
items · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
anyOf · anyOf[38] · object · $ref #/$defs/OrganizationRegistrationChallenge
Single-use control challenge. Every binding field exists to close one replay path: purpose separates this proof from any other signature the organization makes, audience and trust_domain pin it to this deployment, origin pins the HTTP surface, nonce makes it unrepeatable, and the expiry window bounds how long a captured proof stays useful. A registry MUST consume the challenge on the first successful use and atomically persist (challenge_id, canonical_request_digest, outcome). Only a byte-identical retry may return that stored outcome; the same challenge with any different digest is invalid.
* challenge_id · string
pattern: ^ak:organization_registration_challenge:[0-9a-f]{64}$
* organization_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* organization_did · string · $ref ./common-ids.schema.json#/$defs/did
Canonical bare DID used for registration, DID method resolution and owner-published current resolution. It contains no path, query or fragment and MUST project through the registered method adapter to exactly one did_core_id.
pattern: ^did:[a-z0-9]+:[^\s/?#]+$
* purpose · const "ak.organization_registration_control_proof.v1"
Fixed purpose tag, identical to the signing context of OrganizationControlProof.proofs[]. A proof produced for any other purpose MUST NOT verify here.
enum: "ak.organization_registration_control_proof.v1"
* nonce · string
pattern: ^[A-Za-z0-9_-]{22,128}$
* audience_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* origin · string (uri) · format=uri · $ref ./common-ids.schema.json#/$defs/web_origin
Canonical HTTP(S) Web Origin: lowercase scheme/host plus an optional valid non-default effective port. Userinfo, path (including a trailing slash), query, fragment, explicit :80 on HTTP, and explicit :443 on HTTPS are forbidden.
pattern: ^(?:http://(?:\[[0-9A-Fa-f:.]+\]|[a-z0-9](?:[a-z0-9.-]*[a-z0-9])?)(?::(?!80$)(?:[1-9]|[1-9][0-9]{1,3}|[1-5][0-9]{4}|6[0-4][0-9]{3}|65[0-4][0-9]{2}|655[0-2][0-9]|6553[0-5]))?|https://(?:\[[0-9A-Fa-f:.]+\]|[a-z0-9](?:[a-z0-9.-]*[a-z0-9])?)(?::(?!443$)(?:[1-9]|[1-9][0-9]{1,3}|[1-5][0-9]{4}|6[0-4][0-9]{3}|65[0-4][0-9]{2}|655[0-2][0-9]|6553[0-5]))?)$
* trust_domain · string · $ref ./common-ids.schema.json#/$defs/trust_domain
pattern: ^ak:trust_domain:[a-z0-9][a-z0-9._\-:]{0,127}$
* local_admin_subject_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* requested_scopes · array<$ref #/$defs/OrganizationRegistrationScope>
items · string (enum) · $ref #/$defs/OrganizationRegistrationScope
Closed set of local administrative scopes a registration may delegate. organization_profile_manage covers this deployment's local organization profile and display; organization_realm_endorse permits issuing ak.realm.organization statements on the organization's behalf; organization_service_delegate permits declaring organization-to-service delegations locally. The set is closed because an open scope vocabulary would let a deployment mint authority the organization never consented to. Holding a scope is a permission to act later, not an action: registration by itself creates no Realm, membership, governance-Station authority, capability or service delegation.
enum: "organization_profile_manage" "organization_realm_endorse" "organization_service_delegate"
* expires_at · string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
* created_at · string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
anyOf · anyOf[39] · object · $ref #/$defs/OrganizationRegistrationChallengeRequestBody
Request a single-use control challenge for an external Organization DID. Two phases are mandatory: the registry issues the challenge and remembers it, then the caller proves control against it. Folding this into ensure would let the caller supply its own challenge, at which point neither freshness nor single use can be established by the receiver.
* organization_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* organization_did · string · $ref ./common-ids.schema.json#/$defs/did
Canonical bare DID used for registration, DID method resolution and owner-published current resolution. It contains no path, query or fragment and MUST project through the registered method adapter to exactly one did_core_id.
pattern: ^did:[a-z0-9]+:[^\s/?#]+$
* local_admin_subject_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* requested_scopes · array<$ref #/$defs/OrganizationRegistrationScope>
items · string (enum) · $ref #/$defs/OrganizationRegistrationScope
Closed set of local administrative scopes a registration may delegate. organization_profile_manage covers this deployment's local organization profile and display; organization_realm_endorse permits issuing ak.realm.organization statements on the organization's behalf; organization_service_delegate permits declaring organization-to-service delegations locally. The set is closed because an open scope vocabulary would let a deployment mint authority the organization never consented to. Holding a scope is a permission to act later, not an action: registration by itself creates no Realm, membership, governance-Station authority, capability or service delegation.
enum: "organization_profile_manage" "organization_realm_endorse" "organization_service_delegate"
anyOf · anyOf[40] · object · $ref #/$defs/OrganizationRegistrationEnsureRequestBody
Register an external Organization identity with this deployment by submitting both its stable organization_id core and current published organization_did. Idempotent on organization_id: replaying the same registration returns the existing binding with created=false. This operation registers a reference and a local administrative binding; it does not host the DID's method history, does not make this deployment its controller, and does not create Realm state.
* organization_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* organization_did · string · $ref ./common-ids.schema.json#/$defs/did
Canonical bare DID used for registration, DID method resolution and owner-published current resolution. It contains no path, query or fragment and MUST project through the registered method adapter to exactly one did_core_id.
pattern: ^did:[a-z0-9]+:[^\s/?#]+$
* challenge_id · string
pattern: ^ak:organization_registration_challenge:[0-9a-f]{64}$
* version_id · string
The exact resolved DID version the control proof was made against. Pinning the version is what makes the receipt auditable later: without it, a receipt asserts control at an unknown point in the DID's history.
pattern: ^(?!ak:)
* log_head_digest · string
pattern: ^sha256:[0-9a-f]{64}$
* control_proof · object · $ref #/$defs/OrganizationControlProof
Method-native proof that the caller controls the external Organization DID at the pinned version. proof_kind is a closed discriminator with exactly two members, both of which describe a MATURE, already-published DID. Creating a new Organization DID is a separate inception / governance ceremony and deliberately has no member here: a receiver must never have to guess whether a proof asserts control of existing state or creation of new state. This object never carries an Arkret-issued challenge signature in place of method-native control evidence.
allOf · allOf[0] · ?
* proof_kind · string (enum)
resolved_verification_method: a single signature by a verification method that is in the organization DID's control relationship at version_id. governance_quorum: a threshold of signatures from the organization's governance key set. Witness attestation is neither of these and MUST NOT be substituted for control evidence (identity-did.md §8.1).
enum: "resolved_verification_method" "governance_quorum"
quorum_threshold · integer
Required when proof_kind=governance_quorum and forbidden otherwise. The number of distinct valid governance signatures the organization's own policy demands. proofs[] MUST contain at least this many entries signed by distinct verification methods; JSON Schema cannot compare the two, so the receiver MUST enforce it and fail closed when short.
* proofs · array<$ref ./event-envelope.schema.json#/$defs/proof>
Detached proofs over canonical_json({context:'ak.organization_registration_control_proof.v1', challenge_id, organization_id, organization_did, local_admin_subject, version_id, log_head_digest, verification_method, created_at}). The verifier independently validates the published organization_did and requires project(organization_did)=organization_id before checking the DID URL verification_method. Binding the challenge, stable core, DID, beneficiary admin and exact version together prevents replay across deployments, resolutions or beneficiaries.
items · …
recursion truncated at depth 8; see source schema for full shape
* local_admin_subject_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* requested_scopes · array<$ref #/$defs/OrganizationRegistrationScope>
MUST be identical to the set carried by the referenced challenge; a mismatch means the proof was made for different authority than is being claimed.
items · string (enum) · $ref #/$defs/OrganizationRegistrationScope
Closed set of local administrative scopes a registration may delegate. organization_profile_manage covers this deployment's local organization profile and display; organization_realm_endorse permits issuing ak.realm.organization statements on the organization's behalf; organization_service_delegate permits declaring organization-to-service delegations locally. The set is closed because an open scope vocabulary would let a deployment mint authority the organization never consented to. Holding a scope is a permission to act later, not an action: registration by itself creates no Realm, membership, governance-Station authority, capability or service delegation.
enum: "organization_profile_manage" "organization_realm_endorse" "organization_service_delegate"
handle_attestation · object
Optional supporting attestation only. An organization handle or domain claim may improve discovery and display, but MUST NOT substitute for DID control or quorum proof: whoever operates a domain is not thereby the controller of the organization's DID. Named attestation rather than evidence because it carries exactly one material family (common-fields.md R6).
* subject_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* handle · string
* issuer_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* audience · string
* status · string (enum)
The issuer's assertion at signing time. It is a floor, not a guarantee: a receiver MUST still consult the issuer's current revocation state before relying on the handle for display, because a self-asserted active is exactly what a revoked attestation would also carry.
enum: "active" "revoked"
* expires_at · string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
anyOf · anyOf[41] · object · $ref #/$defs/OrganizationRegistrationOutcome
Result of every organization registration command and of the read surface. Identity, DID, generation and version are read from the signed registration_receipt. created is true exactly on a call that opened a new generation.
* registration_receipt · object · $ref #/$defs/OrganizationRegistrationReceipt
Provider-signed record that this deployment accepted an external Organization DID binding. receipt_claims is exactly the object formed by removing registration_receipt_id and proof from the receipt; registration_receipt_id is ak:organization_registration_receipt:<lowercase hex SHA-256(canonical_json(receipt_claims))>. proof.payload_digest hashes the complete receipt after registration_receipt_id is inserted and proof is removed, so neither digest is self-referential. proof is a detached JWS over the ak.organization_registration_receipt_proof.v1 binding object. The receipt proves acceptance of one generation of one local binding and nothing else: it is not a Realm capability, not membership, not a governance-Station designation, and not a service delegation.
* registration_receipt_id · string
ak:organization_registration_receipt: plus lowercase hex SHA-256(canonical_json(receipt with registration_receipt_id and proof both omitted)).
pattern: ^ak:organization_registration_receipt:[0-9a-f]{64}$
* organization_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* organization_did · string · $ref ./common-ids.schema.json#/$defs/did
Canonical bare DID used for registration, DID method resolution and owner-published current resolution. It contains no path, query or fragment and MUST project through the registered method adapter to exactly one did_core_id.
pattern: ^did:[a-z0-9]+:[^\s/?#]+$
* registration_generation · integer
Monotonic generation of the binding for this stable organization did_core_id, starting at 1. A same-core did refresh does not create a different organization identity; terminal registration states remain per generation.
* version_id · string
pattern: ^(?!ak:)
* log_head_digest · string
pattern: ^sha256:[0-9a-f]{64}$
* control_proof_kind · string (enum)
Mirrors OrganizationControlProof.proof_kind so a later auditor can tell which commitment control_key_digest is over without re-fetching the original request.
enum: "resolved_verification_method" "governance_quorum"
* control_key_digest · string
Under resolved_verification_method, the digest of the active control/update public key at version_id. Under governance_quorum, the digest of the canonical governance key set head that satisfied the threshold. It is never a next-key commitment and never private material.
pattern: ^sha256:[0-9a-f]{64}$
* local_admin_subject_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* delegated_scopes · array<$ref #/$defs/OrganizationRegistrationScope>
items · …
recursion truncated at depth 8; see source schema for full shape
* status · string (enum)
Closed lifecycle. active: control evidence is current. stale: the pinned version no longer reflects current control (controller rotation) or the evidence has aged out; low-risk reads may continue but high-risk paths MUST fail closed until a successful refresh. revoked: terminal for this generation, whether withdrawn locally, atomically superseded by a new generation, or forced by deactivation of the external DID. A signed historical receipt can retain status=active as an immutable audit artifact, but it authorizes only while its generation is the registry current generation and that registry state is active.
enum: "active" "stale" "revoked"
* issued_at · string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
* expires_at · string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
* issuer_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* proof · object · $ref ./event-envelope.schema.json#/$defs/proof
Generic detached-JWS proof shape reused by non-Event schemas (snapshot signature, snapshot witness attestations, identity receipts, handle claims, etc.). MUST NOT be used as the shape of Event Envelope `producer_proof` — Event proofs reference $defs/event_proof and bind canonical Event bytes via `event_digest`. Non-Event signed objects MUST define an object-family signing-context constant and include it in the canonical proof binding object with payload_digest; the context constant is not a wire field in this generic shape. drift detection: `payload_digest#event_proof` in forbidden-wire-fields.json is the hard-reject mirror of this rule. New non-Event signed objects MAY $ref this shape; new signed Event-shaped objects MUST instead $ref event_proof.
* kind · …
recursion truncated at depth 8; see source schema for full shape
* verification_method · …
recursion truncated at depth 8; see source schema for full shape
* payload_digest · …
recursion truncated at depth 8; see source schema for full shape
* created_at · …
recursion truncated at depth 8; see source schema for full shape
domain · …
recursion truncated at depth 8; see source schema for full shape
audience · …
recursion truncated at depth 8; see source schema for full shape
proof_purpose · …
recursion truncated at depth 8; see source schema for full shape
* jws · …
recursion truncated at depth 8; see source schema for full shape
* created · boolean
True exactly when this call opened a new generation: the first registration, a re-registration after revoke, or an ensure that changed local_admin_subject or the scope set. False for a byte-identical ensure retry that matches the consumed challenge's canonical_request_digest and stored outcome, and for every read, refresh and revoke. Reusing the challenge with a different digest is an error, not created=false.
anyOf · anyOf[42] · object · $ref #/$defs/OrganizationRegistrationRefreshRequestBody
Re-prove control at a newer resolved version and re-issue the receipt. Scopes are not re-negotiated here; a scope change is a new ensure. Refresh exists because a binding pinned to one version stops proving current control the moment the organization rotates its controller.
* organization_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* organization_did · string · $ref ./common-ids.schema.json#/$defs/did
Canonical bare DID used for registration, DID method resolution and owner-published current resolution. It contains no path, query or fragment and MUST project through the registered method adapter to exactly one did_core_id.
pattern: ^did:[a-z0-9]+:[^\s/?#]+$
* challenge_id · string
pattern: ^ak:organization_registration_challenge:[0-9a-f]{64}$
* version_id · string
pattern: ^(?!ak:)
* log_head_digest · string
pattern: ^sha256:[0-9a-f]{64}$
* control_proof · object · $ref #/$defs/OrganizationControlProof
Method-native proof that the caller controls the external Organization DID at the pinned version. proof_kind is a closed discriminator with exactly two members, both of which describe a MATURE, already-published DID. Creating a new Organization DID is a separate inception / governance ceremony and deliberately has no member here: a receiver must never have to guess whether a proof asserts control of existing state or creation of new state. This object never carries an Arkret-issued challenge signature in place of method-native control evidence.
allOf · allOf[0] · ?
* proof_kind · string (enum)
resolved_verification_method: a single signature by a verification method that is in the organization DID's control relationship at version_id. governance_quorum: a threshold of signatures from the organization's governance key set. Witness attestation is neither of these and MUST NOT be substituted for control evidence (identity-did.md §8.1).
enum: "resolved_verification_method" "governance_quorum"
quorum_threshold · integer
Required when proof_kind=governance_quorum and forbidden otherwise. The number of distinct valid governance signatures the organization's own policy demands. proofs[] MUST contain at least this many entries signed by distinct verification methods; JSON Schema cannot compare the two, so the receiver MUST enforce it and fail closed when short.
* proofs · array<$ref ./event-envelope.schema.json#/$defs/proof>
Detached proofs over canonical_json({context:'ak.organization_registration_control_proof.v1', challenge_id, organization_id, organization_did, local_admin_subject, version_id, log_head_digest, verification_method, created_at}). The verifier independently validates the published organization_did and requires project(organization_did)=organization_id before checking the DID URL verification_method. Binding the challenge, stable core, DID, beneficiary admin and exact version together prevents replay across deployments, resolutions or beneficiaries.
items · …
recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[43] · object · $ref #/$defs/OrganizationRegistrationRevokeRequestBody
Withdraw the local binding. This is a local act with local effect only: it does not modify, deactivate or annotate the external DID's method history, which this deployment does not control.
* organization_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
reason_code · string (enum)
Closed reason set. superseded: replaced by a new binding for the same organization. withdrawn: the deployment or the organization ended the relationship.
enum: "organization_registration_superseded" "organization_registration_withdrawn"
anyOf · anyOf[44] · object · $ref #/$defs/ProjectionMorphList
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* morphs · array<$ref #/$defs/ProjectionMorphRow>
items · object · $ref #/$defs/ProjectionMorphRow
allOf · allOf[0] · …
recursion truncated at depth 8; see source schema for full shape
* morph_id · …
recursion truncated at depth 8; see source schema for full shape
* realm_id · …
recursion truncated at depth 8; see source schema for full shape
* morph_kind · …
recursion truncated at depth 8; see source schema for full shape
title · …
recursion truncated at depth 8; see source schema for full shape
* state · …
recursion truncated at depth 8; see source schema for full shape
state_changed_at · …
recursion truncated at depth 8; see source schema for full shape
stage · …
recursion truncated at depth 8; see source schema for full shape
stage_changed_at · …
recursion truncated at depth 8; see source schema for full shape
created_by · …
recursion truncated at depth 8; see source schema for full shape
created_at · …
recursion truncated at depth 8; see source schema for full shape
updated_at · …
recursion truncated at depth 8; see source schema for full shape
* total · integer
next_cursor · string
pattern: ^ak:cursor:[A-Za-z0-9_-]+$
* has_more · boolean
anyOf · anyOf[45] · object · $ref #/$defs/ProjectionSpaceList
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* spaces · array<$ref #/$defs/ProjectionSpaceRow>
items · object · $ref #/$defs/ProjectionSpaceRow
oneOf · oneOf[0] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · …
recursion truncated at depth 8; see source schema for full shape
* space_id · …
recursion truncated at depth 8; see source schema for full shape
* realm_id · …
recursion truncated at depth 8; see source schema for full shape
* kind · …
recursion truncated at depth 8; see source schema for full shape
title · …
recursion truncated at depth 8; see source schema for full shape
encrypted_metadata · …
recursion truncated at depth 8; see source schema for full shape
parent_space_id · …
recursion truncated at depth 8; see source schema for full shape
rank · …
recursion truncated at depth 8; see source schema for full shape
* state · …
recursion truncated at depth 8; see source schema for full shape
state_changed_at · …
recursion truncated at depth 8; see source schema for full shape
created_by · …
recursion truncated at depth 8; see source schema for full shape
created_at · …
recursion truncated at depth 8; see source schema for full shape
updated_at · …
recursion truncated at depth 8; see source schema for full shape
* total · integer
next_cursor · string
pattern: ^ak:cursor:[A-Za-z0-9_-]+$
* has_more · boolean
anyOf · anyOf[46] · object · $ref #/$defs/ProjectionStrandList
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* strands · array<$ref #/$defs/ProjectionStrandRow>
items · object · $ref #/$defs/ProjectionStrandRow
allOf · allOf[0] · …
recursion truncated at depth 8; see source schema for full shape
* strand_id · …
recursion truncated at depth 8; see source schema for full shape
* realm_id · …
recursion truncated at depth 8; see source schema for full shape
* state · …
recursion truncated at depth 8; see source schema for full shape
state_changed_at · …
recursion truncated at depth 8; see source schema for full shape
stage · …
recursion truncated at depth 8; see source schema for full shape
stage_changed_at · …
recursion truncated at depth 8; see source schema for full shape
title · …
recursion truncated at depth 8; see source schema for full shape
summary · …
recursion truncated at depth 8; see source schema for full shape
topic · …
recursion truncated at depth 8; see source schema for full shape
board_space_id · …
recursion truncated at depth 8; see source schema for full shape
list_space_id · …
recursion truncated at depth 8; see source schema for full shape
rank · …
recursion truncated at depth 8; see source schema for full shape
assigned_actor_ids · …
recursion truncated at depth 8; see source schema for full shape
assigned_to_relations · …
recursion truncated at depth 8; see source schema for full shape
created_by · …
recursion truncated at depth 8; see source schema for full shape
created_at · …
recursion truncated at depth 8; see source schema for full shape
updated_by · …
recursion truncated at depth 8; see source schema for full shape
updated_at · …
recursion truncated at depth 8; see source schema for full shape
* is_default · …
recursion truncated at depth 8; see source schema for full shape
* total · integer
next_cursor · string
pattern: ^ak:cursor:[A-Za-z0-9_-]+$
* has_more · boolean
anyOf · anyOf[47] · object · $ref #/$defs/StrandWatchCurrentRequestBody
Exact self watch selector. It cannot enumerate watchers or supply an expected CAS value.
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* strand_id · string · $ref ./event-payload.schema.json#/$defs/strand_id
pattern: ^ak:strand:[A-Za-z0-9_-]{44}$
* watcher_actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind · …
recursion truncated at depth 8; see source schema for full shape
* account_id · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* kind · …
recursion truncated at depth 8; see source schema for full shape
* service_id · …
recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[48] · oneOf[2] · $ref #/$defs/StrandWatchCurrentOutcome
A verified never-written fact is distinct from a written result whose value was cleared to null.
oneOf · oneOf[0] · object · $ref #/$defs/StrandWatchCurrentNeverWritten
* status · const "never_written"
enum: "never_written"
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* governance_generation · integer
* stream_head · object · $ref ./realm-commit.schema.json#/$defs/stream_head
* stream_ref · …
recursion truncated at depth 8; see source schema for full shape
* stream_position · …
recursion truncated at depth 8; see source schema for full shape
* commit_id · …
recursion truncated at depth 8; see source schema for full shape
* selector · object · $ref ./typed-current-result.schema.json#/$defs/strand_watch_result/properties/selector
* kind · …
recursion truncated at depth 8; see source schema for full shape
* strand_id · …
recursion truncated at depth 8; see source schema for full shape
* watcher_actor_id · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object · $ref #/$defs/StrandWatchCurrentPresent
* status · const "current"
enum: "current"
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* governance_generation · integer
* stream_head · object · $ref ./realm-commit.schema.json#/$defs/stream_head
* stream_ref · …
recursion truncated at depth 8; see source schema for full shape
* stream_position · …
recursion truncated at depth 8; see source schema for full shape
* commit_id · …
recursion truncated at depth 8; see source schema for full shape
* result · object · $ref ./typed-current-result.schema.json#/$defs/strand_watch_result
* selector · …
recursion truncated at depth 8; see source schema for full shape
* source_stream_ref · …
recursion truncated at depth 8; see source schema for full shape
* revision · …
recursion truncated at depth 8; see source schema for full shape
* value · …
recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[49] · object · $ref #/$defs/ServiceRegistrationEnsureRequestBody
* service_kind · string (enum) · $ref #/$defs/ServiceRegistrationKey/properties/service_kind
enum: "station" "identity_registry"
* public_base_url · string (uri) · format=uri · $ref #/$defs/ServiceRegistrationKey/properties/public_base_url
Canonical service base URL: lower-case scheme and host, no query or fragment, normalized path, and exactly one trailing slash. Production deployments MUST use https; explicit development deployments MAY use http.
pattern: ^https?://[^?#]+/$
* did · string · $ref ./common-ids.schema.json#/$defs/did
Canonical bare DID used for registration, DID method resolution and owner-published current resolution. It contains no path, query or fragment and MUST project through the registered method adapter to exactly one did_core_id.
pattern: ^did:[a-z0-9]+:[^\s/?#]+$
* inception_operation · object · $ref #/$defs/ServiceWebvhInceptionOperation
* versionId · string
pattern: ^1-[1-9A-HJ-NP-Za-km-z]+$
* versionTime · string (date-time) · format=date-time
* parameters · object · $ref #/$defs/ServiceWebvhInceptionParameters
* scid · …
recursion truncated at depth 8; see source schema for full shape
* method · …
recursion truncated at depth 8; see source schema for full shape
* updateKeys · …
recursion truncated at depth 8; see source schema for full shape
* nextKeyHashes · …
recursion truncated at depth 8; see source schema for full shape
* state · object · $ref #/$defs/ServiceDidDocument
* @context · …
recursion truncated at depth 8; see source schema for full shape
* id · …
recursion truncated at depth 8; see source schema for full shape
alsoKnownAs · …
recursion truncated at depth 8; see source schema for full shape
* verificationMethod · …
recursion truncated at depth 8; see source schema for full shape
* authentication · …
recursion truncated at depth 8; see source schema for full shape
* assertionMethod · …
recursion truncated at depth 8; see source schema for full shape
* service · …
recursion truncated at depth 8; see source schema for full shape
* proof · array<$ref #/$defs/ServiceWebvhDataIntegrityProof>
items · …
recursion truncated at depth 8; see source schema for full shape
* idempotency_key · string · $ref ./principal-operations.schema.json#/$defs/opaque_id
Bounded opaque caller-chosen correlation string used only to relate audit records for one ensure attempt. It is deliberately outside the ak: typed-ID namespace and MUST NOT be parsed by the typed-ID parser or treated as an object identity. Registration identity is the canonical (service_kind, public_base_url) key that Provider persistence enforces with UNIQUE(service_kind, public_base_url), and the single idempotency authority for this operation is the operation registry's idempotency_mechanism=object_id; this field never establishes a second one.
previous_receipt · oneOf[2]
oneOf · oneOf[0] · object · $ref #/$defs/ServiceRegistrationReceipt
Provider-signed stable service-registration receipt. registration_receipt_id is ak:service_registration_receipt:<lowercase hex SHA-256(canonical_json(receipt claims))>. service_id is the projected did_core_id and did is the verified DID. proof is a detached JWS over the ak.service_registration_receipt_proof.v1 binding object; consumers verify the provider through its own resolution evidence.
* registration_receipt_id · …
recursion truncated at depth 8; see source schema for full shape
* registration_key · …
recursion truncated at depth 8; see source schema for full shape
* service_id · …
recursion truncated at depth 8; see source schema for full shape
* did · …
recursion truncated at depth 8; see source schema for full shape
* version_id · …
recursion truncated at depth 8; see source schema for full shape
* log_head_digest · …
recursion truncated at depth 8; see source schema for full shape
* control_key_digest · …
recursion truncated at depth 8; see source schema for full shape
* issued_at · …
recursion truncated at depth 8; see source schema for full shape
* provider_id · …
recursion truncated at depth 8; see source schema for full shape
* proof · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · null
anyOf · anyOf[50] · object · $ref #/$defs/ServiceRegistrationOutcome
* did_document · object · $ref #/$defs/ServiceDidDocument
* @context · array<string (uri)>
items · …
recursion truncated at depth 8; see source schema for full shape
* id · string · $ref ./common-ids.schema.json#/$defs/webvh_did
Canonical bare did:webvh identifier used at method-native registration, document and evidence boundaries. Role admission is enforced separately.
pattern: ^did:webvh:[^\s:/?#]+:[^\s/?#]+$
alsoKnownAs · array<string (uri)>
items · …
recursion truncated at depth 8; see source schema for full shape
* verificationMethod · array<$ref #/$defs/ServiceDidVerificationMethod>
items · …
recursion truncated at depth 8; see source schema for full shape
* authentication · array<string>
items · …
recursion truncated at depth 8; see source schema for full shape
* assertionMethod · array<string>
items · …
recursion truncated at depth 8; see source schema for full shape
* service · array<$ref #/$defs/ServiceDidEndpoint>
items · …
recursion truncated at depth 8; see source schema for full shape
* registration_receipt · object · $ref #/$defs/ServiceRegistrationReceipt
Provider-signed stable service-registration receipt. registration_receipt_id is ak:service_registration_receipt:<lowercase hex SHA-256(canonical_json(receipt claims))>. service_id is the projected did_core_id and did is the verified DID. proof is a detached JWS over the ak.service_registration_receipt_proof.v1 binding object; consumers verify the provider through its own resolution evidence.
* registration_receipt_id · string
pattern: ^ak:service_registration_receipt:[0-9a-f]{64}$
* registration_key · object · $ref #/$defs/ServiceRegistrationKey
* service_kind · …
recursion truncated at depth 8; see source schema for full shape
* public_base_url · …
recursion truncated at depth 8; see source schema for full shape
* service_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* did · string · $ref ./common-ids.schema.json#/$defs/did
Canonical bare DID used for registration, DID method resolution and owner-published current resolution. It contains no path, query or fragment and MUST project through the registered method adapter to exactly one did_core_id.
pattern: ^did:[a-z0-9]+:[^\s/?#]+$
* version_id · string
pattern: ^(?!ak:)
* log_head_digest · string
pattern: ^sha256:[0-9a-f]{64}$
* control_key_digest · string
Digest of the active control/update public key at version_id; this is not the next-key commitment or private recovery material.
pattern: ^sha256:[0-9a-f]{64}$
* issued_at · string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
* provider_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* proof · object · $ref ./event-envelope.schema.json#/$defs/proof
Generic detached-JWS proof shape reused by non-Event schemas (snapshot signature, snapshot witness attestations, identity receipts, handle claims, etc.). MUST NOT be used as the shape of Event Envelope `producer_proof` — Event proofs reference $defs/event_proof and bind canonical Event bytes via `event_digest`. Non-Event signed objects MUST define an object-family signing-context constant and include it in the canonical proof binding object with payload_digest; the context constant is not a wire field in this generic shape. drift detection: `payload_digest#event_proof` in forbidden-wire-fields.json is the hard-reject mirror of this rule. New non-Event signed objects MAY $ref this shape; new signed Event-shaped objects MUST instead $ref event_proof.
* kind · …
recursion truncated at depth 8; see source schema for full shape
* verification_method · …
recursion truncated at depth 8; see source schema for full shape
* payload_digest · …
recursion truncated at depth 8; see source schema for full shape
* created_at · …
recursion truncated at depth 8; see source schema for full shape
domain · …
recursion truncated at depth 8; see source schema for full shape
audience · …
recursion truncated at depth 8; see source schema for full shape
proof_purpose · …
recursion truncated at depth 8; see source schema for full shape
* jws · …
recursion truncated at depth 8; see source schema for full shape
* created · boolean
anyOf · anyOf[51] · object · $ref #/$defs/SessionGrantIntrospectOutcome
allOf · allOf[0] · ?
* active · boolean
Whether the grant is currently valid for the requested audience. READ-ONLY: introspection never consumes the grant.
* status · string (enum)
enum: "active" "revoked" "superseded" "expired" "locked" "suspended" "audience_mismatch" "proof_required" "invalid_proof" "not_found"
* proof_required · boolean
Whether an additional S2S holder proof is required to confirm the grant active for this introspection request. Default Station grant+DPoP validation uses the request DPoP instead of this field.
* one_time_use_consumed · boolean
Always false: introspection is read-only and never consumes single-use state (rotation is the refresh endpoint's job).
grant · object · $ref #/$defs/SessionGrantIntrospectGrant
Non-secret grant metadata returned to the validating Station. Never includes the grant JWT, refresh token, or session private key.
allOf · allOf[0] · ?
allOf · allOf[1] · ?
allOf · allOf[2] · ?
allOf · allOf[3] · ?
* id · string · $ref ./common-ids.schema.json#/$defs/session_grant_id
pattern: ^ak:session_grant:[A-Za-z0-9_-]{44}$
* issuer_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id · …
recursion truncated at depth 8; see source schema for full shape
* station_id · …
recursion truncated at depth 8; see source schema for full shape
device_id · string · $ref ./common-ids.schema.json#/$defs/device_id
pattern: ^ak:device:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$
* audience_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* scopes · array<string>
items · …
recursion truncated at depth 8; see source schema for full shape
* expires_at · string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
revoked_at · string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
* revocation_ref · string
* session_public_key · string
Session signing key (JWK) for RFC 9421 PoP verification on /_arkret/self/* (api-conventions §3.2). Server-to-server only.
* cnf_jkt · string
RFC 7638 JWK SHA-256 thumbprint of the holder (DPoP) key the grant is bound to (cnf.jkt); the Station uses it to verify the per-request DPoP proof on /_arkret/self/* (api-conventions §3.3). Server-to-server only.
* credential_class · string (enum) · $ref #/$defs/SessionGrantCredentialClass
Closed credential class. recovery_session is a <=15 minute, non-refreshable, DPoP-bound candidate-device grant restricted to the exact recovery operation set; recovery completion issues a distinct standard grant.
enum: "standard" "recovery_session"
* holder_binding · oneOf[3] · $ref ./principal-operations.schema.json#/$defs/session_grant_holder_binding
Required closed accepted human-device, recovery candidate-device, or Agent-runtime holder binding.
oneOf · oneOf[0] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[2] · …
recursion truncated at depth 8; see source schema for full shape
device_binding · object · $ref #/$defs/SessionGrantDeviceBinding
Authorization state committed into a standard device grant. An Account Authority MUST populate it verbatim from the Station TCB current-device decision, which is the only source of the origin-derived authorization Event and generation; it MUST NOT be taken from client input, a local cache or a private lookup. Stations compare it with the current active device generation on admission.
* device_id · …
recursion truncated at depth 8; see source schema for full shape
* authorization_event_id · …
recursion truncated at depth 8; see source schema for full shape
* model_generation_ref · …
recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[52] · object · $ref #/$defs/SessionGrantIntrospectRequestBody
Server-to-server session-grant introspection request. Exactly one of id / grant_jwt identifies the grant.
oneOf · oneOf[0] · ?
oneOf · oneOf[1] · ?
id · string · $ref ./common-ids.schema.json#/$defs/session_grant_id
Grant id. Mutually exclusive with grant_jwt.
pattern: ^ak:session_grant:[A-Za-z0-9_-]{44}$
grant_jwt · string
The signed grant JWT to introspect. Mutually exclusive with id.
audience_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
proof · object
Optional S2S holder confirmation signed by the session key bound into the grant. Stations validating /_arkret/self/* grant+DPoP requests do not require a client-carried introspection proof; they verify the request DPoP locally against the returned cnf_jkt.
* challenge · string
* proof_jwt · string
JWS over ak.session_grant.introspection_proof.v1 claims (session_grant_id, grant_jwt_digest, audience, challenge, issued_at, expires_at).
anyOf · anyOf[53] · object · $ref #/$defs/SessionGrantOutcome
* account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id · $ref #/$defs/did_core_id · $ref #/$defs/did_core_id
* station_id · $ref #/$defs/did_core_id · $ref #/$defs/did_core_id
device_id · string
pattern: ^ak:device:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$
* session_grant · string
Short-lived bearer/session grant bound to the requested principal, device and audience.
* expires_at · string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
* session_grant_id · string · $ref ./common-ids.schema.json#/$defs/session_grant_id
Stable id of the issued or rotated session grant. Returned for every grant so the client can reference, refresh, introspect or revoke this exact grant without re-parsing the opaque session_grant.
pattern: ^ak:session_grant:[A-Za-z0-9_-]{44}$
* session_public_key · string (canonical-public-jwk-jcs) · format=canonical-public-jwk-jcs
JWK of the holder/session key the grant is bound to (the device holder key). The client needs this to perform RFC 9421 PoP and to derive the DPoP cnf.jkt for /_arkret/self/* requests (api-conventions.md §3.2 / §3.3); returning it avoids a mandatory introspect round-trip before the first self-path request.
* audience_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* granted_scope · array<string>
items · string
previous_session_grant_id · string · $ref ./common-ids.schema.json#/$defs/session_grant_id
Present only on refresh. The predecessor grant atomically superseded by this successor.
pattern: ^ak:session_grant:[A-Za-z0-9_-]{44}$
anyOf · anyOf[54] · oneOf[2] · $ref #/$defs/SessionGrantRefreshRequestBody
Closed human-versus-Agent SessionGrant rotation union. Neither branch accepts a client-generated challenge or a generic proof_kind enum.
oneOf · oneOf[0] · object · $ref #/$defs/HumanSessionGrantRefreshRequest
* grant_jwt · string
Near-expiry human DPoP-bound SessionGrant presented as Authorization: DPoP plus a matching DPoP proof.
audience_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* device_id · string · $ref ./common-ids.schema.json#/$defs/device_id
pattern: ^ak:device:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$
* accepted_device_possession_proof · object · $ref #/$defs/AcceptedDevicePossessionProof
Accepted-device Ed25519 possession proof shared by human SessionGrant issue and refresh. The signature covers utf8('ak.session_grant_accepted_device_possession_proof.v1\n') followed by RFC 8785 JCS of this complete object with signature omitted. It is not a server challenge: freshness comes from the <=300 second signed window, the one-time account handoff or predecessor grant, the issuer request identity, and issuer-ledger exact replay. The origin Station MUST verify this proof with the durable current accepted-device key in the same linearization that evaluates current authorization.
allOf · allOf[0] · …
recursion truncated at depth 8; see source schema for full shape
* context · …
recursion truncated at depth 8; see source schema for full shape
* purpose · …
recursion truncated at depth 8; see source schema for full shape
request_id · …
recursion truncated at depth 8; see source schema for full shape
account_subject · …
recursion truncated at depth 8; see source schema for full shape
account_handoff_grant_digest · …
recursion truncated at depth 8; see source schema for full shape
predecessor_session_grant_id · …
recursion truncated at depth 8; see source schema for full shape
* account_id · …
recursion truncated at depth 8; see source schema for full shape
* device_id · …
recursion truncated at depth 8; see source schema for full shape
* audience_id · …
recursion truncated at depth 8; see source schema for full shape
* holder_jkt · …
recursion truncated at depth 8; see source schema for full shape
* session_intent_digest · …
recursion truncated at depth 8; see source schema for full shape
* issued_at · …
recursion truncated at depth 8; see source schema for full shape
* expires_at · …
recursion truncated at depth 8; see source schema for full shape
* verification_method · …
recursion truncated at depth 8; see source schema for full shape
* signature · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object · $ref #/$defs/AgentSessionGrantRefreshRequest
Agent rotation binds the predecessor grant's agent_id, accepted agent_key_authorization_ref and proof.verification_method. Agent MLS endpoints have no device_id; a refresh carrying one is invalid.
* grant_jwt · string
Near-expiry Agent DPoP-bound SessionGrant presented as Authorization: DPoP plus a matching DPoP proof.
audience_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* principal_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* agent_key_authorization_ref · string · $ref ./account-operations.schema.json#/$defs/event_id
pattern: ^ak:event:[A-Za-z0-9_-]{44}$
* agent_session_refresh_proof · object · $ref #/$defs/AgentSessionRefreshProof
Current Agent runtime-key proof for SessionGrant rotation. It is a distinct branch from accepted human-device PoP and carries no client-generated challenge or polymorphic proof_kind.
* context · …
recursion truncated at depth 8; see source schema for full shape
* request_canonical_digest · …
recursion truncated at depth 8; see source schema for full shape
* audience_id · …
recursion truncated at depth 8; see source schema for full shape
* issued_at · …
recursion truncated at depth 8; see source schema for full shape
* expires_at · …
recursion truncated at depth 8; see source schema for full shape
* verification_method · …
recursion truncated at depth 8; see source schema for full shape
* signature · …
recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[55] · object · $ref #/$defs/SessionGrantReplayExpiredProblem
Closed RFC 9457 Problem Details extension members for session_grant_replay_expired. The named issuer-ledger record remains authoritative and no replacement grant is created under the same request identity.
* session_grant_id · string · $ref ./common-ids.schema.json#/$defs/session_grant_id
pattern: ^ak:session_grant:[A-Za-z0-9_-]{44}$
* state · const "expired"
Retained on purpose: this is an RFC 9457 Problem Details extension member on the failure path and names the issuer-ledger state that caused the rejection, so the problem document stays self-describing next to SessionGrantReplayTerminalProblem. It is not a success-only outcome constant.
enum: "expired"
anyOf · anyOf[56] · object · $ref #/$defs/SessionGrantReplayTerminalProblem
Closed RFC 9457 Problem Details extension members for session_grant_replay_terminal. The state is an exact durable issuer-ledger terminal state and no replacement grant is created under the same request identity.
* session_grant_id · string · $ref ./common-ids.schema.json#/$defs/session_grant_id
pattern: ^ak:session_grant:[A-Za-z0-9_-]{44}$
* state · string (enum)
enum: "revoked" "superseded"
anyOf · anyOf[57] · oneOf[3] · $ref #/$defs/SessionGrantRequestBody
Closed returning-human, Agent runtime or fresh-device recovery issuance union. OIDC authorization codes are consumed only by account_handoff_request_body and never by this operation.
oneOf · oneOf[0] · object · $ref #/$defs/HumanSessionGrantRequest
Returning-human issuance from an already bound account. Authorization is the DPoP-bound account_handoff_grant plus matching per-request DPoP; the body deliberately carries neither a second holder signature nor requested_scope.
* request_id · string
pattern: ^ak:request:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$
* principal_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* device_id · string · $ref ./common-ids.schema.json#/$defs/device_id
pattern: ^ak:device:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$
* audience_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* accepted_device_possession_proof · object · $ref #/$defs/AcceptedDevicePossessionProof
Accepted-device Ed25519 possession proof shared by human SessionGrant issue and refresh. The signature covers utf8('ak.session_grant_accepted_device_possession_proof.v1\n') followed by RFC 8785 JCS of this complete object with signature omitted. It is not a server challenge: freshness comes from the <=300 second signed window, the one-time account handoff or predecessor grant, the issuer request identity, and issuer-ledger exact replay. The origin Station MUST verify this proof with the durable current accepted-device key in the same linearization that evaluates current authorization.
allOf · allOf[0] · …
recursion truncated at depth 8; see source schema for full shape
* context · …
recursion truncated at depth 8; see source schema for full shape
* purpose · …
recursion truncated at depth 8; see source schema for full shape
request_id · …
recursion truncated at depth 8; see source schema for full shape
account_subject · …
recursion truncated at depth 8; see source schema for full shape
account_handoff_grant_digest · …
recursion truncated at depth 8; see source schema for full shape
predecessor_session_grant_id · …
recursion truncated at depth 8; see source schema for full shape
* account_id · …
recursion truncated at depth 8; see source schema for full shape
* device_id · …
recursion truncated at depth 8; see source schema for full shape
* audience_id · …
recursion truncated at depth 8; see source schema for full shape
* holder_jkt · …
recursion truncated at depth 8; see source schema for full shape
* session_intent_digest · …
recursion truncated at depth 8; see source schema for full shape
* issued_at · …
recursion truncated at depth 8; see source schema for full shape
* expires_at · …
recursion truncated at depth 8; see source schema for full shape
* verification_method · …
recursion truncated at depth 8; see source schema for full shape
* signature · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object · $ref #/$defs/AgentSessionGrantRequest
Agent runtime session issuance is bound to principal_id (agent_id), proof.verification_method and the current accepted agent_key_authorization_ref. This closed branch MUST NOT carry a device_id or derive one from the Agent key.
* principal_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* requested_scope · array<string>
items · …
recursion truncated at depth 8; see source schema for full shape
* agent_key_authorization_ref · string
`ak.profile.agent_auth.v1` overlay. Event ref of the accepted `ak.agent.key.authorize` that authorized the runtime key. REQUIRED when `proof.proof_kind="agent_key_proof"`; MUST be omitted for human session grants.
pattern: ^ak:event:[A-Za-z0-9_-]{44}$
* agent_scope_request · object
`ak.profile.agent_auth.v1` overlay. Narrowing hints for the issued session scope. Service-surface requested_scope values are intersected with the immutable provision requested_scope, accepted agent_key_scope and endpoint/resource policy; content actions are additionally intersected with independent effective Realm capability grants, participation, membership, history visibility and E2EE policy. Provision mandatory constraints remain in force at every layer. REQUIRED when `proof.proof_kind="agent_key_proof"`; MUST be omitted for human session grants. `track_names` is a request-side narrowing field only — the materialized session grant MUST express track scope via the canonical `allowed_tracks` constraint, not via a new `track_names` grant.
realm_ids · …
recursion truncated at depth 8; see source schema for full shape
strand_ids · …
recursion truncated at depth 8; see source schema for full shape
track_names · …
recursion truncated at depth 8; see source schema for full shape
requested_scope_disclosure · object · $ref ./agent-requested-scope-disclosure.schema.json
Controller-signed, verifier-bound private disclosure of an Agent's immutable requested_scope. This object is authorization evidence, not a grant. It MUST travel only over an authenticated confidential presentation/operation channel and MUST NOT be written to a public DID Document, durable Realm Event, public registry, pairing code, or notification. The verifier consumes request_id/challenge once, validates the short presentation window, verifies a current controller proof, recomputes the requested-scope commitment against the accepted-at Agent DID commitment, and then applies the Agent ceiling subset rules. After successful one-time admission, an implementation MAY retain the object only as encrypted verifier-private evidence keyed by the recomputed digest, verifier_id and audience.
* schema · …
recursion truncated at depth 8; see source schema for full shape
* request_id · …
recursion truncated at depth 8; see source schema for full shape
* agent_id · …
recursion truncated at depth 8; see source schema for full shape
* controller_principal_id · …
recursion truncated at depth 8; see source schema for full shape
* requested_scope · …
recursion truncated at depth 8; see source schema for full shape
* verifier_id · …
recursion truncated at depth 8; see source schema for full shape
* audience · …
recursion truncated at depth 8; see source schema for full shape
* challenge · …
recursion truncated at depth 8; see source schema for full shape
* issued_at · …
recursion truncated at depth 8; see source schema for full shape
* expires_at · …
recursion truncated at depth 8; see source schema for full shape
* proofs · …
recursion truncated at depth 8; see source schema for full shape
* dpop_binding_proof · object · $ref #/$defs/SessionGrantDpopBindingProof
`ak.profile.agent_auth.v1` overlay. DPoP proof JWT for the holder key that the issued session grant will bind to. REQUIRED when `proof.proof_kind="agent_key_proof"`; the Account Authority verifies the proof and materializes the resulting JWK thumbprint into the issued grant's `cnf.jkt` / session_public_key binding.
* proof_jwt · …
recursion truncated at depth 8; see source schema for full shape
* proof · object
Closed initial Agent proof. Require 0 < expires_at-issued_at <= 300 seconds, issued_at <= now+30 seconds, and now < expires_at for first validation. No additional nonce. Exact completed issuer-ledger replay reuses durable one-shot verification, with fresh matching-holder HTTP DPoP.
* proof_kind · …
recursion truncated at depth 8; see source schema for full shape
* challenge · …
recursion truncated at depth 8; see source schema for full shape
* request_canonical_digest · …
recursion truncated at depth 8; see source schema for full shape
* audience_id · …
recursion truncated at depth 8; see source schema for full shape
* issued_at · …
recursion truncated at depth 8; see source schema for full shape
* expires_at · …
recursion truncated at depth 8; see source schema for full shape
* verification_method · …
recursion truncated at depth 8; see source schema for full shape
* signature · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[2] · object · $ref #/$defs/RecoverySessionGrantRequest
Fresh-device existing-principal recovery issuance. Authorization is the Bound AccountHandoff plus matching per-request DPoP. The Account Authority binds this request to its account/principal mapping and does not consume the handoff on success.
* credential_class · const "recovery_session"
enum: "recovery_session"
* request_id · string
pattern: ^ak:request:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$
* principal_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* device_id · string · $ref ./common-ids.schema.json#/$defs/device_id
pattern: ^ak:device:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$
* audience_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
anyOf · anyOf[58] · object · $ref #/$defs/SignalSubmitOutcome
Result of transient Signal admission. accepted=true means the service placed the encrypted envelope on the short-lived rail; it creates no Event, RealmCommit, authority-stream position or durable delivery receipt.
* accepted · boolean
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* envelope_digest · string
Digest of the admitted complete encrypted envelope, used only for short-lived replay suppression and local correlation.
pattern: ^(sha256|blake3):[0-9a-f]{64}$
dispatched_recipient_count · integer
Optional implementation hint for fanout recipients queued locally.
server_received_at · string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
anyOf · anyOf[59] · object · $ref #/$defs/SignedSessionGrantClaims
Canonical signed claims carried by an ak.session.grant JWT. Except for the fixed kind and derived jti, the closed issuance preimage fields are copied from these claims. credential_class and holder_binding are signed and jointly determine the authorization profile; recovery_session is never refreshable or upgradable and recovery completion issues a distinct standard credential. Verifiers MUST RFC 8785-canonicalize the complete claim-derived preimage, recompute SHA-256, prepend the active sha256 suite wire code, derive ak:session_grant:<44-char-token>, and require byte equality with jti. Changing either binding therefore changes the ID.
allOf · allOf[0] · ?
allOf · allOf[1] · ?
* kind · const "ak.session.grant"
enum: "ak.session.grant"
* jti · string · $ref ./common-ids.schema.json#/$defs/session_grant_id
pattern: ^ak:session_grant:[A-Za-z0-9_-]{44}$
* issuer_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* issuance_nonce · string
Canonical unpadded Base64URL encoding of the issuer-generated 256-bit issuance nonce. Exact replay reuses the same nonce, issuance preimage, grant ID and JWT.
pattern: ^[A-Za-z0-9_-]{43}$
* account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id · $ref #/$defs/did_core_id · $ref #/$defs/did_core_id
* station_id · $ref #/$defs/did_core_id · $ref #/$defs/did_core_id
* session_public_key · string (canonical-public-jwk-jcs) · format=canonical-public-jwk-jcs
A supported public JWK serialized as its exact RFC 8785 JCS UTF-8 string. Producers MUST parse and canonicalize input before signing; consumers MUST reject strings whose parsed JWK re-serialization is not byte-identical. Private JWK members are forbidden.
* audience_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* scopes · array<string>
items · string
* not_before · string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
* expires_at · string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
* session_id · string
pattern: ^(?!ak:)
* credential_class · string (enum) · $ref #/$defs/SessionGrantCredentialClass
Closed credential class. recovery_session is a <=15 minute, non-refreshable, DPoP-bound candidate-device grant restricted to the exact recovery operation set; recovery completion issues a distinct standard grant.
enum: "standard" "recovery_session"
device_binding · object · $ref #/$defs/SessionGrantDeviceBinding
Authorization state committed into a standard device grant. An Account Authority MUST populate it verbatim from the Station TCB current-device decision, which is the only source of the origin-derived authorization Event and generation; it MUST NOT be taken from client input, a local cache or a private lookup. Stations compare it with the current active device generation on admission.
* device_id · string · $ref ./common-ids.schema.json#/$defs/device_id
pattern: ^ak:device:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$
* authorization_event_id · string
pattern: ^ak:event:[A-Za-z0-9_-]{44}$
* model_generation_ref · integer · $ref ./recovery-session.schema.json#/$defs/pcr_generation_ref
PCR-local monotonic generation. It MUST NOT equal or be derived from a DID versionId.
* holder_binding · oneOf[3] · $ref ./principal-operations.schema.json#/$defs/session_grant_holder_binding
oneOf · oneOf[0] · object
* kind · …
recursion truncated at depth 8; see source schema for full shape
* device_binding · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* kind · …
recursion truncated at depth 8; see source schema for full shape
* agent_id · …
recursion truncated at depth 8; see source schema for full shape
* agent_key_authorization_ref · …
recursion truncated at depth 8; see source schema for full shape
* verification_method · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[2] · object
* kind · …
recursion truncated at depth 8; see source schema for full shape
* device_id · …
recursion truncated at depth 8; see source schema for full shape
proof_kind · string (enum)
enum: "account_handoff" "agent_key_proof"
scope_details · object
anyOf · anyOf[60] · oneOf[2] · $ref #/$defs/CommittedEventView
Caller-scoped, non-durable read representation pairing one RealmCommit with either the exact producer-signed Event or a minimal withheld marker. It has no independent identity, signature or persistence semantics and is never reducer input.
oneOf · oneOf[0] · object
* commit · object · $ref ./realm-commit.schema.json
The only shared Realm acceptance, ordering, finality and replication record. Every visibility scope has an authority-signed predecessor chain.
allOf · allOf[0] · …
recursion truncated at depth 8; see source schema for full shape
* commit_id · …
recursion truncated at depth 8; see source schema for full shape
* realm_id · …
recursion truncated at depth 8; see source schema for full shape
* stream_ref · …
recursion truncated at depth 8; see source schema for full shape
* stream_position · …
recursion truncated at depth 8; see source schema for full shape
* previous_commit_ref · …
recursion truncated at depth 8; see source schema for full shape
* event_ref · …
recursion truncated at depth 8; see source schema for full shape
* governance_generation · …
recursion truncated at depth 8; see source schema for full shape
* authority_ref · …
recursion truncated at depth 8; see source schema for full shape
* committed_at · …
recursion truncated at depth 8; see source schema for full shape
producer_signer_fact_digest · …
recursion truncated at depth 8; see source schema for full shape
* signature · …
recursion truncated at depth 8; see source schema for full shape
* event · allOf[2] · $ref ./event-envelope.schema.json#/$defs/shared_event_envelope
allOf · allOf[0] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* commit · object · $ref ./realm-commit.schema.json
The only shared Realm acceptance, ordering, finality and replication record. Every visibility scope has an authority-signed predecessor chain.
allOf · allOf[0] · …
recursion truncated at depth 8; see source schema for full shape
* commit_id · …
recursion truncated at depth 8; see source schema for full shape
* realm_id · …
recursion truncated at depth 8; see source schema for full shape
* stream_ref · …
recursion truncated at depth 8; see source schema for full shape
* stream_position · …
recursion truncated at depth 8; see source schema for full shape
* previous_commit_ref · …
recursion truncated at depth 8; see source schema for full shape
* event_ref · …
recursion truncated at depth 8; see source schema for full shape
* governance_generation · …
recursion truncated at depth 8; see source schema for full shape
* authority_ref · …
recursion truncated at depth 8; see source schema for full shape
* committed_at · …
recursion truncated at depth 8; see source schema for full shape
producer_signer_fact_digest · …
recursion truncated at depth 8; see source schema for full shape
* signature · …
recursion truncated at depth 8; see source schema for full shape
* event_disclosure · object · $ref #/$defs/EventDisclosure
Caller-scoped marker stating that canonical Event bytes are withheld. It carries no Event identity, reason, digest, preview or reducer input.
* status · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] · object
context · const "ak.realm_commit_signature.v1"
enum: "ak.realm_commit_signature.v1"
* event_disclosure · object · $ref #/$defs/EventDisclosure
Caller-scoped marker stating that canonical Event bytes are withheld. It carries no Event identity, reason, digest, preview or reducer input.
* status · const "withheld"
enum: "withheld"

Source