跳转到内容

ak.schema.signal_stream_frame.v1

← Schemas

SignalStreamFrame
ak.schema.signal_stream_frame.v1 · file: schemas/signal-stream-frame.schema.json

One frame emitted by ak.self.signal.stream.subscribe.v1. Signal data is encrypted-only and ephemeral. Control frames never create a cursor, replay position, delivery receipt, or durable acceptance.

* $ · oneOf[4]
One frame emitted by ak.self.signal.stream.subscribe.v1. Signal data is encrypted-only and ephemeral. Control frames never create a cursor, replay position, delivery receipt, or durable acceptance.
oneOf · oneOf[0] · object · $ref #/$defs/signal
* kind · const "signal"
enum: "signal"
* envelope · object · $ref ./signal-envelope.schema.json
Encrypted-only broadcast signal envelope. Exact product payload type and target are inside encrypted_payload. This object is never a durable Event and never advances RealmCommit coverage or reducer state.
oneOf · oneOf[0] · ?
oneOf · oneOf[1] · ?
allOf · allOf[0] · ?
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* scope_ref · oneOf[4] · $ref ./event-envelope.schema.json#/$defs/scope_ref
oneOf · oneOf[0] · object
* kind · const "realm"
enum: "realm"
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
oneOf · oneOf[1] · object
* kind · const "circle"
enum: "circle"
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* circle_id · string · $ref ./common-ids.schema.json#/$defs/circle_id
pattern: ^ak:circle:[A-Za-z0-9_-]{44}$
oneOf · oneOf[2] · object
Native controller-and-owned-Agents private scope. It is not a Circle and has no editable membership.
* kind · const "sidecar"
enum: "sidecar"
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* sidecar_id · string · $ref ./common-ids.schema.json#/$defs/sidecar_id
pattern: ^ak:sidecar:[A-Za-z0-9_-]{44}$
oneOf · oneOf[3] · object
Genesis scope for ak.realm.create only. It carries no realm_id because the receiver derives every Realm id, including Collaboration, Direct Conversation, human PCR, and Agent PCR, as retype(event_id, "realm") from this create Event (zh/models/realm-and-space.md section 2.5.0). The uniform omission also prevents the digest cycle.
* kind · const "realm_genesis"
enum: "realm_genesis"
* sender_actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind · const "account"
enum: "account"
* account_id · $ref #/$defs/account_id · $ref #/$defs/account_id
oneOf · oneOf[1] · object
* kind · const "service"
enum: "service"
* service_id · $ref #/$defs/did_core_id · $ref #/$defs/did_core_id
sender_device_id · string · $ref ./common-ids.schema.json#/$defs/device_id
Closed sender discriminator: required exactly for an ordinary account-device sender and absent exactly for an Agent sender. null and sentinels are forbidden. Absence only selects the candidate Agent branch; source and recipient still verify accepted Agent classification and current runtime authority.
pattern: ^ak:device:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$
* authority_commit_id · string · $ref ./common-ids.schema.json#/$defs/realm_commit_id
Content-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern: ^ak:realm_commit:[A-Za-z0-9_-]{44}$
parent_realm_authority_commit_id · string · $ref ./common-ids.schema.json#/$defs/realm_commit_id
Content-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern: ^ak:realm_commit:[A-Za-z0-9_-]{44}$
* signal_class · string (enum)
enum: "setup" "moderation" "session"
* sent_at · string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
* expires_at · string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
* encrypted_payload · object
AEAD ciphertext. The AAD is the JCS bytes of the closed pre-encryption header projected from the envelope top level, this object's scheme/key_ref/purpose/aead_profile/epoch/nonce and the verified group state (zh/sync/signal.md section 1); it is rebuilt by the recipient and never carried as an aad_digest. Exact payload kind, product target, and sender sequence exist only in plaintext after recipient decryption. The scheme names the construction, never the algorithm: aead_profile carries the algorithm and MUST equal the active MLS ciphersuite the group at key_ref.group_state_ref actually negotiated (zh/conformance/encoding.md section 10.1), so key_ref carries no algorithm mirror. Activating a further ciphersuite therefore reaches Signal with no wire change.
* scheme · const "ak.signal_exporter_aead.v1"
enum: "ak.signal_exporter_aead.v1"
* key_ref · object
* group_state_ref · oneOf[2]
Accepted ak.mls.genesis / winning ak.mls.commit for the scope's MLS group, or an equivalent group state proof hash. It is what fixes which ciphersuite aead_profile must equal.
oneOf · oneOf[0] · string
pattern: ^ak:event:[A-Za-z0-9_-]{44}$
oneOf · oneOf[1] · string
pattern: ^(sha256|blake3):[0-9a-f]{64}$
* purpose · const "ak.signal.v1"
AEAD purpose for this domain. It is a nonce-derivation and AAD input, so it keeps a Signal nonce from colliding with a content-encryption nonce under the same key and epoch.
enum: "ak.signal.v1"
* aead_profile · string
canonical_id of an active row of artifacts/registry/mls-ciphersuite-registry.json. It MUST equal the ciphersuite the group at key_ref.group_state_ref actually negotiated; a reserved suite, an unregistered suite, or a mismatch MUST fail closed.
* epoch · integer
* nonce · string
pattern: ^[A-Za-z0-9_-]{16}$
* ciphertext · string
pattern: ^[A-Za-z0-9_-]+$
* proof · $ref #/$defs/signal_proof · $ref #/$defs/signal_proof
* delivery_authority · object · $ref #/$defs/delivery_authority
Own-Station current admission for only the exact envelope in this authenticated stream frame. Bound to the receiving account and live connection generation; never a transferable or reusable current grant. The client independently binds key and exact authorization_ref to its verified MLS leaf.
* recipient_account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id · $ref #/$defs/did_core_id · $ref #/$defs/did_core_id
* station_id · $ref #/$defs/did_core_id · $ref #/$defs/did_core_id
* key · object · $ref ./signer-key-operations.schema.json#/$defs/station_signing_key
* actor · $ref #/$defs/signing_account_actor_id · $ref #/$defs/signing_account_actor_id
* verification_method · string (uri) · format=uri
pattern: ^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$
* public_key_b64u · string
Canonical unpadded base64url of exactly 32 Ed25519 public-key bytes; this is public material, not reusable current authorization.
pattern: ^[A-Za-z0-9_-]{42}[AEIMQUYcgkosw048]$
* authorization_ref · string · $ref ./common-ids.schema.json#/$defs/event_id
Complete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern: ^ak:event:[A-Za-z0-9_-]{44}$
oneOf · oneOf[1] · object · $ref #/$defs/heartbeat
* kind · const "heartbeat"
enum: "heartbeat"
oneOf · oneOf[2] · object · $ref #/$defs/drain
* kind · const "drain"
enum: "drain"
reconnect_after_ms · integer
reason · string
oneOf · oneOf[3] · object · $ref #/$defs/unauthorized
* kind · const "unauthorized"
enum: "unauthorized"
reason · string

Source