ak.schema.space.v1
ak.schema.space.v1 · file: schemas/space.schema.json A Space is a structural grouping object inside a Realm. Boards, lists, swimlanes, calendar buckets, document outline groups, etc. are all Spaces. Authorization-transparent: never carries its own membership/policy/E2EE group; its metadata may be placed in an existing Realm/Circle effective scope via scope_circle_id.
* $ · object
A Space is a structural grouping object inside a Realm. Boards, lists, swimlanes, calendar buckets, document outline groups, etc. are all Spaces. Authorization-transparent: never carries its own membership/policy/E2EE group; its metadata may be placed in an existing Realm/Circle effective scope via scope_circle_id.
allOf · allOf[0] ·
?allOf · allOf[1] ·
?allOf · allOf[2] · oneOf[2]
oneOf · oneOf[0] ·
?oneOf · oneOf[1] · object
fields ·
objectid ·
stringPresent on the materialised object. MUST be absent from the create Event payload: zh/models/common-fields.md derives it from the create Event's own event_id (retyped), so a payload-supplied id would be a second, forgeable truth.
pattern:
^ak:space:[A-Za-z0-9_-]{44}$* schema ·
const "ak.schema.space.v1"enum:
"ak.schema.space.v1"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$scope_circle_id ·
string · $ref ./common-ids.schema.json#/$defs/circle_idOptional Circle scope for this Space object's own metadata and scoped structural relation facts. Space still does not own a security boundary; it only places its metadata into an existing Circle scope. Omitted means Realm-default scope.
pattern:
^ak:circle:[A-Za-z0-9_-]{44}$child_scope_policy · object · $ref #/$defs/child_scope_policy
Reducer-enforced placement/encryption policy for child resources created in or moved into this Space.
allOf · allOf[0] ·
?* kind ·
string (enum)enum:
"allow_any" "require_e2ee" "require_same_scope" "require_scope_circle_id"scope_circle_id ·
string · $ref ./common-ids.schema.json#/$defs/circle_idpattern:
^ak:circle:[A-Za-z0-9_-]{44}$parent_space_id ·
stringOptional canonical parent, which MUST belong to the same actual realm_id. Cross-Realm parent is forbidden, including at creation, with failed_precondition / space_realm_mismatch. Missing or unverifiable parent evidence fails closed with space_parent_unreadable before disclosing Realm differences.
pattern:
^ak:space:[A-Za-z0-9_-]{44}$* kind ·
stringSpace kind. v1 standard kinds include 'space', 'project', 'folder', 'board', 'list', and 'topic'. Profile-defined kinds (e.g., 'swimlane', 'calendar_bucket', 'page_group') MAY be added via Realm schema/profile and MUST be registered. Unknown kind MUST schema_violation.
rank ·
stringFractional-index rank within parent. See encoding.md §9.
pattern:
^[0-9A-Za-z]{1,128}$schema_refs · array<string>
Optional schema/profile references that further constrain this Space's contained Strand types, fields, or position invariants.
items ·
stringtitle ·
string (arkret-single-line-display-text) · format=arkret-single-line-display-text · $ref string-profiles.schema.json#/$defs/display_text_256NFC multilingual single-line display text; mixed scripts, emoji, and symbols are allowed.
pattern:
^[^\u0000-\u001F\u007F-\u009F\u202A-\u202E\u2066-\u2069\uFEFF]*[^\s\u0000-\u001F\u007F-\u009F\u202A-\u202E\u2066-\u2069\uFEFF][^\u0000-\u001F\u007F-\u009F\u202A-\u202E\u2066-\u2069\uFEFF]*$summary ·
string (arkret-short-text) · format=arkret-short-text · $ref string-profiles.schema.json#/$defs/short_textNFC multilingual short text. LF is allowed; CR, other C0/C1 controls, BOM, and bidi embedding/override controls are rejected.
pattern:
^[^\u0000-\u0009\u000B-\u001F\u007F-\u009F\u202A-\u202E\uFEFF]*$labels · array<string>
items ·
stringfields · object
Space kind-specific fields. For kind=list, wip_limit is an integer 1..100000 and wip_limit_enforcement is required with enum warn|reject|require_review whenever wip_limit is present; these are the sole write-policy source and MUST NOT be read from View. For kind=board, view_id may identify a default presentation. MUST NOT contain a 'rank' key (rank is a top-level Space field; see relation.md §2 for the symmetric Relation constraint and forbidden-wire-fields.json `fields.rank/space_payload`).
wip_limit ·
integerwip_limit_enforcement ·
string (enum)enum:
"warn" "reject" "require_review"avatar_blob_ref ·
stringpattern:
^ak:blob:(?:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}|(?:sha256|blake3):[0-9a-f]{64})$encrypted_metadata · object · $ref ./encrypted-envelope.schema.json
Minimal ciphertext wire. purpose, effective scope and Event kind come from the frozen signed outer Event; mls_group_id is derived from that scope. The canonical pre-encryption header is reconstructed and is not duplicated on wire.
* version ·
const "1.0"enum:
"1.0"* content_type ·
stringpattern:
^[a-z0-9.+-]+/[a-z0-9.+-]+$* encryption_context ·
$ref #/$defs/encryption_context · $ref #/$defs/encryption_context* ciphertext ·
stringpattern:
^[A-Za-z0-9_-]+$state ·
string (enum)Space lifecycle state. 'active' is the default. State transitions are reducer-enforced per common-fields.md §5.1: ak.space.archive MUST come from state=='active' (else failed_precondition reason=space_not_active); ak.space.restore MUST come from state=='archived' (else failed_precondition reason=space_not_archived); ak.space.tombstone MUST come from {'active','archived'} AND must have no live dependents (failed_precondition reason=space_already_terminal for terminal source, space_has_live_dependents for live refs). Same-state self-transitions (archive on archived, etc.) MUST fail; clients re-archive by restore-then-archive. Tombstoned is irreversible (MUST NOT be restored). The transition timestamp lives on the writing Event and on state_changed_at.
enum:
"active" "archived" "tombstoned"state_changed_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* created_by · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind ·
const "account"enum:
"account"* account_id ·
$ref #/$defs/account_id · $ref #/$defs/account_idoneOf · oneOf[1] · object
* kind ·
const "service"enum:
"service"* service_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_id* created_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$updated_by · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind ·
const "account"enum:
"account"* account_id ·
$ref #/$defs/account_id · $ref #/$defs/account_idoneOf · oneOf[1] · object
* kind ·
const "service"enum:
"service"* service_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_idupdated_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$Source
- registry row:
spec/v1/artifacts/registry/schema-registry.json - schema document:
spec/v1/artifacts/schemas/space.schema.json