跳转到内容

ak.schema.signal_envelope.v1

← Schemas

Arkret Signal Envelope
ak.schema.signal_envelope.v1 · file: schemas/signal-envelope.schema.json

Encrypted-only broadcast signal envelope. Exact product payload type and target are inside encrypted_payload. This object is never a durable Event and never advances RealmCommit coverage or reducer state.

* $ · object
Encrypted-only broadcast signal envelope. Exact product payload type and target are inside encrypted_payload. This object is never a durable Event and never advances RealmCommit coverage or reducer state.
oneOf · oneOf[0] · ?
oneOf · oneOf[1] · ?
allOf · allOf[0] · ?
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* scope_ref · oneOf[4] · $ref ./event-envelope.schema.json#/$defs/scope_ref
oneOf · oneOf[0] · object
* kind · const "realm"
enum: "realm"
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
oneOf · oneOf[1] · object
* kind · const "circle"
enum: "circle"
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* circle_id · string · $ref ./common-ids.schema.json#/$defs/circle_id
pattern: ^ak:circle:[A-Za-z0-9_-]{44}$
oneOf · oneOf[2] · object
Native controller-and-owned-Agents private scope. It is not a Circle and has no editable membership.
* kind · const "sidecar"
enum: "sidecar"
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* sidecar_id · string · $ref ./common-ids.schema.json#/$defs/sidecar_id
pattern: ^ak:sidecar:[A-Za-z0-9_-]{44}$
oneOf · oneOf[3] · object
Genesis scope for ak.realm.create only. It carries no realm_id because the receiver derives every Realm id, including Collaboration, Direct Conversation, human PCR, and Agent PCR, as retype(event_id, "realm") from this create Event (zh/models/realm-and-space.md section 2.5.0). The uniform omission also prevents the digest cycle.
* kind · const "realm_genesis"
enum: "realm_genesis"
* sender_actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind · const "account"
enum: "account"
* account_id · $ref #/$defs/account_id · $ref #/$defs/account_id
oneOf · oneOf[1] · object
* kind · const "service"
enum: "service"
* service_id · $ref #/$defs/did_core_id · $ref #/$defs/did_core_id
sender_device_id · string · $ref ./common-ids.schema.json#/$defs/device_id
Closed sender discriminator: required exactly for an ordinary account-device sender and absent exactly for an Agent sender. null and sentinels are forbidden. Absence only selects the candidate Agent branch; source and recipient still verify accepted Agent classification and current runtime authority.
pattern: ^ak:device:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$
* authority_commit_id · string · $ref ./common-ids.schema.json#/$defs/realm_commit_id
Content-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern: ^ak:realm_commit:[A-Za-z0-9_-]{44}$
parent_realm_authority_commit_id · string · $ref ./common-ids.schema.json#/$defs/realm_commit_id
Content-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern: ^ak:realm_commit:[A-Za-z0-9_-]{44}$
* signal_class · string (enum)
enum: "setup" "moderation" "session"
* sent_at · string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
* expires_at · string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
* encrypted_payload · object
AEAD ciphertext. The AAD is the JCS bytes of the closed pre-encryption header projected from the envelope top level, this object's scheme/key_ref/purpose/aead_profile/epoch/nonce and the verified group state (zh/sync/signal.md section 1); it is rebuilt by the recipient and never carried as an aad_digest. Exact payload kind, product target, and sender sequence exist only in plaintext after recipient decryption. The scheme names the construction, never the algorithm: aead_profile carries the algorithm and MUST equal the active MLS ciphersuite the group at key_ref.group_state_ref actually negotiated (zh/conformance/encoding.md section 10.1), so key_ref carries no algorithm mirror. Activating a further ciphersuite therefore reaches Signal with no wire change.
* scheme · const "ak.signal_exporter_aead.v1"
enum: "ak.signal_exporter_aead.v1"
* key_ref · object
* group_state_ref · oneOf[2]
Accepted ak.mls.genesis / winning ak.mls.commit for the scope's MLS group, or an equivalent group state proof hash. It is what fixes which ciphersuite aead_profile must equal.
oneOf · oneOf[0] · string
pattern: ^ak:event:[A-Za-z0-9_-]{44}$
oneOf · oneOf[1] · string
pattern: ^(sha256|blake3):[0-9a-f]{64}$
* purpose · const "ak.signal.v1"
AEAD purpose for this domain. It is a nonce-derivation and AAD input, so it keeps a Signal nonce from colliding with a content-encryption nonce under the same key and epoch.
enum: "ak.signal.v1"
* aead_profile · string
canonical_id of an active row of artifacts/registry/mls-ciphersuite-registry.json. It MUST equal the ciphersuite the group at key_ref.group_state_ref actually negotiated; a reserved suite, an unregistered suite, or a mismatch MUST fail closed.
* epoch · integer
* nonce · string
pattern: ^[A-Za-z0-9_-]{16}$
* ciphertext · string
pattern: ^[A-Za-z0-9_-]+$
* proof · object · $ref #/$defs/signal_proof
Detached sender proof over canonical_json({context:'ak.signal_proof.v1', envelope_digest, sender_actor_id, sender_device_id?, verification_method, created_at, domain?, audience?}). sender_device_id exists only for the ordinary branch and is omitted for Agent. envelope_digest hashes the complete SignalEnvelope with proof removed. The transcript member created_at is injected from the outer sent_at (x-arkret-binding-field-sources) and is not a wire member of this proof. Source and recipient authenticate current endpoint authority and verify this producer signature. Peer destination validates closed proof/transcript structure and recomputed digest, not the producer signature or remote authority; recipient must independently authenticate before display or effects (zh/sync/signal.md section 3).
* kind · const "detached_jws"
enum: "detached_jws"
* verification_method · string
The DID URL bare DID component MUST project through its registered adapter to the signing principal component of sender_actor_id (account_id.principal_id for account). Ordinary requires fragment == sender_device_id. Agent requires the complete method byte-identical to the current accepted Agent signing-key binding and forbids sender_device_id. Constructing a method by appending to did_core_id is forbidden. The projection does not establish Station, Agent classification, or authority. Source and recipient independently bind current exact endpoint authority; destination validates projection and transcript structure but does not query remote authority or verify the producer signature as a relay prerequisite.
pattern: ^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$
* envelope_digest · string · $ref #/$defs/digest
pattern: ^(sha256|blake3):[0-9a-f]{64}$
domain · string
audience · oneOf[2]
oneOf · oneOf[0] · string
oneOf · oneOf[1] · array<string>
items · string
* jws · string
pattern: ^[A-Za-z0-9_-]+\.\.[A-Za-z0-9_-]+$

Source