Skip to content

Service HTTP Binding

This content is not available in your language yet.

Service HTTP 绑定

规范关键字按规范语言解释。HTTP path、method、operation ID、request/response schema 和错误映射的唯一机器真相源是 operation-registry.json、arkret-service-api.openapi.yaml 和 operations-error-mapping.json。本页只规定 authority-commit 切换后的绑定边界,不维护一份并行端点全表。

章节编号是稳定引用身份(normative):本页的编号小节都是正文,各自承载自己的完整义务。 编号是供其它领域页稳定引用的身份,不表达阅读顺序,MUST NOT 被理解为「只保留号、内容在别处」的占位别名。 引用本页某节即引用该节正文。

1. Surface 分层

  • /_arkret/gate/* 是无 Realm 会话前置流程;它不能接纳 Realm Event。
  • /_arkret/self/* 由已认证账号调用自己的 Account Station。
  • /_arkret/peer/* 只用于验证过的 Station-to-Station 转发、复制和计划 handoff。
  • /_arkret/open/* 只返回明确登记的公开对象;返回 locator 不等于证明 authority。

所有非 open 端点必须在解析大型 body 之前执行身份、audience、重放窗口和字节上限检查。 未授权的 hidden Realm/Circle/Sidecar 必须使用不可枚举的统一失败形态。

2. HTTP 端点与 Event 提交

2.1 REST API 命名空间组织

gate/self/peer/open/root/edge/find/server 前缀只表达认证与网络边界,不改变同一 operation 的 typed schema 和 authority-commit 语义。

2.1.2 Account authentication

Account 认证和 session grant 在 gate/self 边界完成,不因其成功而绕过 Realm Event 的 authority commit。

2.2 端点契约规则

每个端点必须绑定唯一 operation ID、request/response schema、auth profile、body class 和错误集。

2.2.2 Service authentication

Station-to-Station 请求必须绑定 exact source/destination service identity、operation ID、body digest 和重放窗口。

2.2.3 Deployment-internal channel

同一 Station TCB 内部的函数、RPC、标准认证 provider API、journal 与 outbox 都是实现细节,不登记 canonical operation,也不得借用 peer operation 假装成跨服务互操作。实现 MAY 为拆进程或拆库选择私有认证与恢复机制, 但其内部请求、receipt 和中间态不得进入 operation registry、HTTP binding、schema、fixture 或 conformance surface。

所有部署都必须在公开 operation 的边界上给出相同结果:current-device、generation、revocation pending、proof、 session/DPoP 与 intent 的判定 fail closed;成功的 Event、唯一 RealmCommit 与 terminal outcome 可 exact replay; 未知或不确定内部状态不得扩大公开信息。只有确实跨独立 service identity 与治理边界的调用才使用本章的 Station-to-Station binding。

2.2.4 请求材料供给闭合(normative)

供给闭合律:合同中出现的每一个”需要”,必须在 machine-readable 合同里有一个登记在案的 “从哪来”。 对每个 operation 请求 schema 的必填输入,其来源 MUST 落在以下封闭集合之一, 不在集合内即为合同缺陷,release gate 拒绝:

  1. 调用方自产(client_local)——调用方本地生成或签署的材料:自签 detached-JWS / Data Integrity proof、本地密钥与密文、自由内容、协议参数、幂等键与 nonce、对自己所 授权内容的摘要,以及签发者就是调用方本人的签名声明(如 join-policy 的 applicant/reviewer receipt);
  2. 已登记供给(supplied)——某已登记 operation 响应、或客户端经 sync 可达的 event payload,按 $def 同一性返回同一对象;仅当字段为无 $ref 的内联标量时才允许 按字段名逐字一致供给(echo 纪律,见下),$ref 对象不得靠同名字段跨域冒充;
  3. 带内绑定(in-band binding)——开放对象仅当兄弟成员以 const 声明其封闭 schema 身份 (request_schema 模式)、或以 canonical_bytes_base64url + digest 钉死字节时放行;
  4. 结构面规则(structural surface)——ak.peer.* / ak.edge.* 的提交方是服务器 / applet host,本地投影即来源;ak.open.* 是带外 handoff 面(二维码 / 外部协议), 输入按定义来自 HTTP 合同之外;由 DID log 读取面按方法自有形态派生的引用 (did_generation_ref 等)视为已供给;
  5. 具名例外——登记于 request-material-supply-exemption-registry.json, disposition 封闭为 external_form / open_finding / deferred_supply 三值; open_finding / deferred_supply 行 MUST 引用 arkret-work 中仍存在的评审条目锚点, 对应缺口闭合时 MUST 同变更删行;结构性类别 MUST NOT 以例外行承载——例外表只收 逐条人工背书的个案。

配套规则:

  • 无形状必填禁止:additionalProperties: true 且无任何 shape 成员的必填对象,除非命中 第 3 类带内绑定或具名例外(external_form),一律拒绝——散文描述不是形状。
  • echo 容器纪律(002 / 010 落盘形态的提升):读取面为下一步写入交付材料时,MUST 使用 专用容器(如 next_prepare_input / next_replace_input),成员名与写入面消费的字段 逐字节一致;时态语义由容器名承担,MUST NOT 引入改名映射。读取面缺料时省略容器即 “当前不可 author”,MUST NOT 为此新增错误码或状态枚举。
  • 交付形态选择指南(non-normative):验证方自持的状态快照优先不透明游标(CAS 载体); 对端签名事实优先返回完整签名对象使客户端可自行验证;跨信任域提交的证据 MUST 由服务器 在 server-to-server 一跳承运(carrier 附带),客户端不亲手跨域搬运。
  • 联合分支可构造性:必填字段为 oneOf 联合时,每一条分支都必须整体可构造——分支 可能由准入上下文钦定而非调用方自由选择,存在不可构造分支的联合按缺陷上报,确属可选 分支的经具名例外承载。
  • FSM 入口闭合:transition_contracts 每个 cell family MUST 恰好声明 initial_state / initial_states / template 三者之一(键集封闭),且所有已声明状态 MUST 从入口集经已登记 cell write 可达、所有 allowed_transitions MUST 有对应写入、 const→const 写入 MUST 不越表——这是 OPEN-FLOW-PROTO-013 当初缺失的那道门。

机器门禁:tools/artifact_lint 的 request_material_supply 与 fsm_reachability, 随 release gate --strict 强制执行;例外表与本节双向绑定(门禁查表 + 反向校验行未失效)。

2.3 幂等与不确定结果

exact Event retry 必须返回同一 committed outcome;同 Event ID 但 canonical bytes 不同必须 duplicate_conflict 且零写入。请求者在 response 丢失后重放原字节,不得重签或生成新幂等身份。

2.4 上传与二进制传输

Blob 和其它 binary operation 使用各自登记的 streaming/binary body contract,不与 Event submit 共用 JSON 上限。

2.4.1 Content digest

引用别名(normative pointer):本节不独立新增义务;Content-Digest 的全部规范内容见 §8.2 Peer signature 与 content-digest。

2.6 Self 提交

POST /_arkret/self/events 接受 authority-commit-operations.schema.json#/$defs/self_submit_request,返回 #/$defs/self_submit_outcome。普通 EventAdmissionSubmission 与 MLS Commit 保持各自单提交合同; ordinary_realm_bootstrap 是按 contract-registry.json.realm_bootstrap_registry.ordinary_collaboration 固定 slot 顺序、在同一治理 Station/Realm stream 上整体接纳或整体回滚的原子分支; direct_conversation_founding 是恰四条有序 Event 的原子分支;membership_compensation 是一条 Event、 closed transport-only evidence 与 single-use CAS 的原子分支。Account Station 必须先耐久保存 exact producer-signed bytes,再解析 current authority bundle 并转发;没有验证到 authority-signed RealmCommit 时不得返回 committed 或对其它成员 fanout。这里没有 schema 外的 queued/forwarding success body。wire_scope=actor_private_event 的 kind 不经本 operation 接纳:MUST 以 unsupported_event_kind 零写入拒绝, 它们只走 ../models/actor-private-effects.md §2.1 登记的专用提交 operation。

ordinary_realm_bootstrap 以 UUIDv7 idempotency_key 与完整 caller-signed EventAdmissionSubmission[] 提交;每条 Event 单独取得连续 RealmCommit,成功与 exact replay 均按原顺序返回同一批完整 source Commit,失败不产生部分成功。 旧 service-operation-dtos.schema.json#/$defs/EventsSubmitBatchRequestBody 只供 security-transaction.schema.json#/$defs/prepared_event_unit 内嵌使用,不是此 HTTP operation 的通用 batch 分支。以后若登记独立 Event 的便捷 batch,必须 另行定义逐项 outcome、无 staged 同批依赖与无整组原子性;本 operation 当前 不接受 caller 自选任意 Event 集合或 atomic=true。

旧 Seal-style 的 pending-control 查询、prepare/fence 与 submit 命令不属于 v1 公开 operation 或 HTTP binding;服务 MUST NOT 暴露这些路径作为第二套 Event 接纳、frontier 或设备撤销状态真相源。设备 revocation_pending 仍由 device-lifecycle.md §5.5.3 的 durable proposal 与 covering RealmCommit command result 折叠,pairing/current-device gate 仍必须 fail closed;移除旧路由不得删除这些事实或改变本节正式 Event submit 的事务与幂等语义。

2.7 Peer 转发

POST /_arkret/peer/events 接受 authority-commit-operations.schema.json#/$defs/peer_submit_request,返回 #/$defs/peer_submit_outcome。它是唯一 peer Event ingress,但 body 不是语义含混的通用 batch:closed branch 只允许下列三项,解析边界必须拒绝混支字段。

  • authority_forward:携一条 exact EventAdmissionSubmission 或一份 MLS Commit submission,只允许已验证的 forwarding Station 调用 exact current governance Station;仅后者执行首次 admission 并签发新 RealmCommit。本分支另有唯一成员 producer_device_evidence(account_device_signer_evidence),其有无由 Event 决定:实际签名方是 Account 且 proof fragment 为 ak:device: 时必带,其它情况禁带,MLS 以 Commit Event 的 producer 为准;缺失或多余为 schema_violation。forwarding Station 每次转发尝试前现签并先持久化,治理 Station 按 ../crypto-media/device-lifecycle.md §8.2.2 验证后才接纳; 其它两支不得携带它。event_submission 的 Event 是 ak.mls.genesis 时必带、其它 kind 禁带 mls_genesis_material(Genesis 所引两个 Blob 的原始字节),治理 Station 核对内容寻址后在接纳事务内保存 (../crypto-media/encryption-and-audit.md §5.1.2)。 Agent runtime producer 改用正式 sibling producer_agent_evidence,human device/service producer 禁带; 同携两个 producer evidence 或缺 required evidence 为 schema_violation 且零写入。实际 producer 以 executed_by(存在时)否则 actor_id 为准,MLS 以 Commit Event 为准。其完整 AccountId、 ASRE ref/key、完整 PCR 闭包、独立 controller gate 与历史服务方法按 key-management.md §3.6.1 验证并在首接纳事务原子保留; compact state cache miss 为 dependency_missing,只能经同一 ingress 完整重交,不新增取回端点。
  • committed_replication:携 replications[1..100];每项直接是 {event_submission: EventAdmissionSubmission, source_commit: RealmCommit},其中 event_submission 只能是 {event: 完整 source Event};approval_signatures MUST 省略,带该成员的 item 为 schema_violation 且零写入。 authority_forward 首次准入仍将原提交中的审批证据送达治理 Station;治理 Station 在本地事务保留私密审计, 复制接收方只依 Event/source Commit 与本机可验证的当前事实判定复制资格,不重审首次审批。 source Event 为 ak.mls.commit 时可另携 目标 service 托管的 recipient 的 welcomes[](其它 kind 禁带),接收方在同一 replica 事务按本地 claim ledger 复核并入队 (../crypto-media/encryption-and-audit.md §2.2)。processing、committed_event wrapper、recipient_witnesses 与 destination echo 均不存在。接收方逐项验证 event/commit/ref、source authority generation、同 stream 连续性;producer proof 只按 federation.md §3 的 “非治理接收方以治理签名为准”核对自身一致与治理签名,不独立解析外站 human 设备 key;并只从自己已验证的 committed membership history/typed current projection 求值本机托管成员的 scope、history、reference disclosure 与 plaintext visibility;发送方字段不得 充当 membership proof。依赖缺失时 fail closed。接收方只保存 exact source bytes,不得重做首次 admission、 重签 Commit 或创建第二轮 fanout。response 的同序 replication_outcomes[] 只允许 {status:"stored"|"duplicate"} 或 {status:"rejected",reason_code};数组位置已绑定输入项,故不重复 index 或 committed_ref,也不把 replica persistence 称为 accepted finality。
  • registered_atomic_unit:只允许 registry 内的 Direct Conversation founding 与 membership compensation。 整个 unit 要么 materialize、要么零写;不存在 per-item partial。DC dependency 缺口使用 direct_conversation_founding_missing_dependency_list 的有界 typed set。

三支都使用 operation registry 登记的 canonical_hash/full_body/retry_safe=true。response 丢失时只能重放 逐字节相同完整 body,并返回原 branch outcome(包括逐项顺序与首次 stored 状态);首次 stored 的同请求 exact replay MUST NOT 改报 duplicate。duplicate 仅表示另一个完整请求首次处理该项时已有相同 source Event / Commit。请求结果的耐久保存 MUST 与所表示的写入同事务;同 hash 异 body 为 duplicate_conflict。请求必须使用 service-to-service authentication 绑定 source/destination service identity、operation、body digest 与有界时间窗。 同一 replication request 内的 source coordinates 必须唯一;同一 stream 的项按 stream_position 严格升序, 不同 stream 的逐项连续性与失败互不回滚。重复 coordinates 或同 stream 乱序在处理任何项前拒绝整个 request。

2.8 普通消息的完整 authoring 准备

普通消息必须在客户端形成 immutable producer-signed Event,再使用统一 Event submit 进入 current authority;准备接口不保留位置也不产生 accepted 结果。

本地明文意图与加密 wire 请求是两件事(normative):ak.self.messages.command.prepare.v1 的 intent.content 是一个封闭 oneOf——kind="plaintext" 承载本地明文意图,kind="mls" 承载已经加密好的 wire 请求(encrypted_content 与 encryption_context)。两者 MUST NOT 混用或互相回退。在已由 accepted ak.mls.genesis 激活的 effective scope 中,kind="plaintext" 的 prepare 请求 MUST 被拒绝 (../crypto-media/encryption-and-audit.md §2.3);准备接口 MUST NOT 代替客户端加密,Station 在该 scope 中 MUST NOT 取得明文。

加密与校验都在客户端(normative):客户端 MUST 先按 §2.3 冻结该条消息的 AAD 输入并在本地完成加密, 再发出 prepare 请求。收到 draft 后,客户端 MUST 把 draft 中的 ciphertext、加密 metadata 与全部绑定 (effective scope、Event kind、encryption_context、引用的 public group revision)与自己冻结、送出的那份 逐字节比对,任一不符 MUST 丢弃该 draft 并 fail closed,MUST NOT 就地改写 draft 后签名。

精确重试不消耗第二个 sender counter(normative):prepare 结果不明确时,客户端 MUST 重放 byte-identical 的同一请求。该重试 MUST NOT 重新加密,因此 MUST NOT 推进 RFC 9420 sender ratchet 的 generation,也 MUST NOT 产生第二份 ciphertext。为同一条消息生成第二份 ciphertext 会使已冻结的 AAD 与已送出的那份不再唯一对应。

MLS current 失配的唯一拒绝身份(normative):kind="mls" 的 prepare 以及后续 self/peer authority-forward Event submit,在治理 Station 确定 scope 没有 accepted ak.mls.genesis/current group 时 MUST 返回通用 failed_precondition(无专用 reason),不得写入;客户端必须先激活 scope 或改发明文,不得 exact retry 期待该密文成功。 Station 暂时无法读取自身 current MLS 结果时两入口均 MUST 返回 temporarily_unavailable,仅在未产生 Commit 时允许 byte-identical exact retry。若 current scope 已有覆盖当前 key-access checkpoint 的 winning Commit,但冻结的 epoch、 group_state_ref 或 key_access_revision 与 current mls_group result 不符,MUST 返回顶层 epoch_mismatch(HTTP 409);客户端验证并取得 current 本地 MLS state 后重新加密、构造新请求。若 current scope 尚待 winning Commit 覆盖,MUST 优先返回 failed_precondition + epoch_update_required,客户端暂停 发送并等待或促成 repair Commit。已接受历史 Event 的读取/重放与 peer committed replication 按历史 binding 验证,不套用 current send gate。

两请求路径假定发送就绪与本地 MLS state(normative):prepare + submit 这条两请求路径假定调用方已经 send-ready 且已持有目标 epoch 的本地 MLS state。prepare MUST NOT 授予权限、MUST NOT 预留 sequence、 MUST NOT 推进任何 stream 的 RealmCommit.stream_position,也 MUST NOT 建立、修复或代替本地 MLS state; 缺少这些前提时失败发生在客户端加密阶段,而不是由准备接口补齐。

3. 读取与同步

3.1 Stream scan

POST /_arkret/self/streams/scan 一次只扫描一条 caller 获准的 Realm、Circle 或 Sidecar stream。 request 指定 stream_ref、limit 与恰好一个位置参数——after_position(朝更新)或 before_position(朝更旧,历史回填)——方向由选用哪个参数给出,没有独立的方向字段; 两者同时出现或都不出现是 schema 违规,服务端 MUST NOT 代为选一个默认方向。取 null 分别表示 从该 caller 获准读取的最旧位置、从该 caller 获准读取的最新位置起,而不是物理流首与物理流头。 response 返回连续 RealmCommit 及其可见 Event。

边界是 caller 的允许区间,不是物理整流(normative):truncated 只表示所选方向上还有该 caller 获准读取的 Commit。扫到允许区间上端(after_position)或下端(before_position)时它必须为 false, 即使 Station 还持有该 caller 不获准读取的 Commit。不获准读取的历史 MUST NOT 置 truncated, 停在 floor 的一页 MUST NOT 当作截断呈现,truncated 也 MUST NOT 用来遮盖 floor 的存在。 committed_events[] 为空且 truncated=false 只表示该方向上该 caller 的允许区间已扫完, 不表示物理流为空、不存在或没有更多 Commit。

floor 连续性 anchor(normative):扫到允许区间下端的每一页 MUST 携带 readable_floor (oldest_position、该位置的 floor_commit_id、floor_reason),使受限成员不必拿到 position 0 就能把自己获准前缀的下边界绑定到已接受的链上。floor_commit_id 指向的 Commit 是唯一允许其 previous_commit_ref 无法被该 caller 解析的可读 Commit。该 anchor 只证明获准前缀从哪里开始, 既不证明 Station 没有更早历史,也不证明 Station 没有更新的更新。只有该 caller 在这条流上 没有任何可读 Commit 时才省略它,那也是空 committed_events[] + truncated=false 唯一合法的情形。

链校验在两个方向上是同一条等式(normative):页内与跨页都按相邻位置检查,而不是按数组下标—— position 较大那一行的 previous_commit_ref 必须等于 position 较小那一行的 commit_id, 无论该邻居是数组的前一项还是后一项、来自本页还是上一页。倒序分页因此保留本页末行作为下一页的 anchor; position 连续性按 ±1 检查,readable_floor.oldest_position 以下的缺失不是 gap。

逐页示例(物理流 0..12,该 caller 因 join floor 只获准 4..9,limit=3;F 表示 readable_floor = {oldest_position: 4, floor_commit_id: C4, floor_reason 取成员加入这一档}):

请求返回 positiontruncatedreadable_floor
before_position: null9, 8, 7trueF(可带)
before_position: 76, 5, 4false(停在下端,不是截断)F(必带)
after_position: null4, 5, 6trueF(必带,首行即下端)
after_position: 9空false(10..12 不获准,不置 truncated)F(可带)
该 caller 在本流无任何可读 Commit空false省略

该面不使用 cursor:单条 stream 内 stream_position 是严格 +1 全序,位置本身就是续传凭据, 续页由客户端取本批的最大 / 最小 stream_position 得到。响应不返回 prev_cursor / next_cursor / has_more,服务端也不得在此接受 ak:cursor: 值(api-conventions.md §7.2)。 目标 Realm policy 对该 caller 拒绝 Event disclosure,或该 Event 已按 retention 到期时,CommittedEventView 使用 closed withheld 分支 {commit,event_disclosure:{status:"withheld"}};允许披露时使用 full 分支 {commit,event},且 event.event_id MUST 等于 commit.event_ref。不等则 caller MUST 拒绝该项,MUST NOT 二者取一或试图调和。 验证 Commit 不是 Event disclosure 判定;实现 MUST NOT 因为 caller 能验证 Commit 就交出完整 canonical payload bytes。两种分支都只由既有 Commit 定位,不产生新的资源 ID、签名或存储对象;只有 full 分支可作 reducer 输入。

POST /_arkret/peer/streams/scan 使用相同 schema,但要求调用 Station 对该具体 stream 具有复制权。

必须同时给出 event_id、commit_id、stream_ref 与 stream_position。响应返回匹配的 RealmCommit + Event。调用方必须对缺项、任一字段不匹配、Commit 签名失败或 authority chain 不成立 fail closed。该操作用于 Directory 首次 ingest 等精确依赖验证,不得退化为按 Event ID 返回未提交 Event,也不得通过扫描另一条 stream 补齐。 获准 Realm stream 不自动授权 Circle 或 Sidecar stream。

3.1.4 Typed current 读取

Typed current operation 只接受封闭 selector union。响应中的 revision 是最后影响该 typed row 的 Commit ID 与 stream position;不接受 caller 提供的通用 state key,也不暴露其它 stream head。

3.1.5 Realm fanout delivery status(normative)

QUERY /_arkret/self/events/delivery-status(ak.self.events.read.delivery_status.v1)以封闭 {event_id} 请求读取一个 caller-visible、已接受 Event 的完整 frozen target set。服务 MUST 先执行与 该 Event 资源读取相同的可见性判定;未知与不可见统一返回 not_found。读取 MUST NOT 解析新 route、 推进 retry、改变 intent 状态或创建第二轮 fanout。

响应 targets[] 按唯一 target_id 的字节序严格递增。target_id 是 16–128 字符的稳定 opaque id, MUST NOT 编码 service DID。状态封闭为 pending_route、pending_delivery、delivered 与 cancelled_authority_lost;前两者计入 consumer 派生的 pending count,后两者不计入。aggregate state 由 consumer 派生为“pending count 非零即 pending,否则 complete”,不得另设可漂移的服务端汇总字段。 service_id 仅当 caller 按当前 membership、history 与 plaintext visibility 可以读取至少一个产生该 target 的 joined-member ActorId routing projection 时出现,否则 MUST 省略。

ak.self.events.command.submit.v1 的当前 authority-commit outcome 只报告本地 commit/duplicate/拒绝; 它不承诺全部 remote target 已交付,也不重复返回 target 集或 pending count。需要投递进度的 consumer MUST 使用本读取面,并把这里的完整 rows 作为派生 pending count 的唯一输入。

3.2 Snapshot + tail

首次 join、新设备和缓存修复使用 authority-signed typed snapshot,再从 snapshot 内每条获准 stream head 的下一 position 拉取 tail。Snapshot 内联 current_state_entries[] typed current rows,不包含独立 typed current result chunk、通用 state root 或隐藏 stream 的 position。历史可见性仍由 join/history/retention policy 决定,不默认拉全历史。

3.3 站间操作

站间操作只包含 registry 已登记的 Event 转发、逐 stream 复制、authority bundle 与计划 handoff。

3.3.1.1 Discovery 投影

Directory、Invite 和分享链接只能提供 realm_id、authority locator candidate 和必要的 bootstrap hint。 客户端必须向 candidate 请求 nonce-bound authority bundle,从 Realm genesis 连续验证 old→new handoff chain, 然后才接受 current authority 的 snapshot/tail。

3.3.3 Peer 权威复制

Peer 复制只交付已签 RealmCommit、exact Event、typed snapshot 和获准的当前投影。消费 Station 验证 authority chain 和逐 stream 连续性,不重做一份可导出不同 accepted 结果的本地治理判决。

4. Authority discovery 与更换

4.1 Nonce-bound bundle

POST /_arkret/open/realm-authority/bundle 返回 realm-authority-bundle.schema.json。响应必须绑定 request nonce、Realm genesis、连续 handoff records、current generation/service identity 和公开 Realm stream head。 locator、TLS endpoint 或 DID route 只用来找到候选服务,不作为治理权证明。

4.2 Planned handoff

POST /_arkret/peer/realm-authority/handoff 只安装 old/new Station 对同一 transition body 的双签 handoff。 transition body 绑定完整 typed snapshot digest 和所有 Realm/Circle/Sidecar stream heads 的私有 manifest digest。旧方在精确 cut 后永久拒写;新方未完整导入时不得启动任何 stream。

旧 authority 丢失且没有已完成 handoff 时,HTTP 层不定义 takeover、管理员自封或备份恢复写权。

5. MLS

MLS Genesis 与 Commit 仍是 producer-signed Event,由 current governance Station 接纳。Add Commit 使用 mls-commit-submission.schema.json,将 exact Commit Event 和所有 producer-signed Welcome delivery 作为一个原子请求; 任一 delivery 缺失、超限、claim 不匹配或 proof 无效时整体零写入。

Commit 成功后立即成为 winning epoch,本站 recipient 的 Welcome 由治理 Station 的 recipient queue 耐久重试,跨站 recipient 的 Welcome 随 Commit 的 committed-replication item 投到其 Account Station;不等待接收者 ACK 才提交。Station 只验证 RFC 9420 公开 transition、roster、sender 和 key_access_revision, 不持有 MLS private group state。

5.1 MLS 运输

MLS private bytes 保持端到端加密;Station 只处理公开 transition 和 recipient-addressed Welcome ciphertext。

6. 错误与缓存

ak.self.realm_join.command.prepare.v1 对已获准披露的目标,在无法取得可验证 current governance Station、所有候选不可达,或候选材料不能形成唯一且一致的已验证 current authority 结论时,MUST 返回 revision_unavailable(503),不得生成 draft、预留 Event / Commit 或回退到 caller-selected Station。未知或不可见目标、无效 invitation 与不允许该 intent 的 join policy 仍按该 operation 的统一 not_found(404);只有已验证 current pre-state 与 caller intent 不再匹配时才返回 failed_precondition(409)。网络或暂态失败不得伪造权威缺席、position 0 或默认 basis。

  • schema_violation:closed schema、canonical encoding 或 typed ID 失败。
  • 目标不是验证后的 current authority:使用已登记的 authority bundle 验证失败面,不输出未登记的顶层码。
  • expected position/predecessor 与当前 stream head 不符:使用 revision_stale;领域 CAS 不符使用 cas_conflict。
  • cas_conflict:typed payload 的领域 expected_revision 不符。
  • epoch_mismatch:发送请求冻结的 MLS epoch/group-state/key-access revision 与已就绪的 current group 不符。
  • duplicate_conflict:相同幂等身份或内容 ID 对应不同 canonical bytes。
  • temporarily_unavailable:可安全 exact retry,且未产生 Commit。

包含授权结果、authority bundle、snapshot、Commit 或 Welcome 的响应默认 Cache-Control: no-store。 缓存的 public locator 必须遵循短 TTL,并在每次写入前重新验证 authority chain。

7. 非 HTTP 绑定

gRPC、WebSocket 和 MQ 可以复用同一 operation 和 schema,但不得创造 HTTP 不具有的 accepted 状态、 跨 stream 总序或更弱的 proof 验证。所有 transport 的幂等、字节上限、错误语义和权限必须等价。

7.1 Canonical non-HTTP binding closure(normative)

contract-registry.json#operation_registry.operations 的 grpc 与 mq 是非 HTTP 绑定名称的 canonical source。non-http-bindings.yaml 是其完整投影:每个 grpc 值 MUST 恰好出现为 grpc.services.<Service>.<Method> 对应的 Service/Method,每个 mq 值 MUST 恰好出现为 mq.topics 的 topic key;投影不得改名、遗漏、重复 operation,也不得保留零方法 service。 除显式 http_only_variant=true 的 operation 外,每条已登记 operation MUST 至少由一个非 HTTP binding 引用;http_only_variant=true 的 operation MUST NOT 出现在该投影中。生成器和 lint 内部的 operation 集合只能是 canonical operation 集的子集,删除 operation 时不得留下静默失效的硬编码成员。

8. HTTP Message Signature

Arkret 的 RFC 9421 HTTP Message Signature 有五个签名场景:一般 Station-to-Station 服务签名、 单跳 signal envelope peer relay、Applet transaction push 的逐次投递来源签名、客户端会话 PoP 出示, 以及 MIMI provider-to-provider 服务签名。五者共用同一份 canonical 合同——contract-registry.json 的 http_signature_contract_registry。共同覆盖基线、各场景扩展项与其触发条件、必需 signature parameters 与时效窗口数值都只在那里编辑;本页与其它正文、conformance profile、向量描述都是它的 投影,MUST NOT 各自维护自己的覆盖集数组或窗口常量。本节是这些投影的唯一正文归宿, signature_window_invalid 的判据也在这里,MUST NOT 从本页其它编号小节重新推导。

8.1 覆盖集(normative)

凡按合同要求携带 RFC 9421 签名的请求,其 Signature-Input MUST 恰好解析到一个已登记的签名场景, 并覆盖该场景对本次请求适用的全部必需项。

  • 覆盖集是下界,不是闭集:实现 MAY 额外覆盖其它组件;缺任何一个适用必需项 MUST 验签失败, 返回 http_signature_invalid。
  • created / expires 是 RFC 9421 signature parameters,不是覆盖项成员,MUST NOT 被写进覆盖集。
  • RFC 9421 的有序组件列表仍用于构造基串并写入审计记录;本页给出的是集合语义, MUST NOT 被读成对顺序的额外协议要求。需要限定顺序时 MUST 另有明确合同。
  • 五个场景共有的必需项由 canonical 合同的 common_contract 持有,并已逐条展开进下面 每个场景块;本页不另列一份摘要清单,避免出现第二份可独立漂移的副本。 其中 arkret-operation 的全局义务来自 api-conventions.md §2.4.1: 凡要求 RFC 9421 签名的 canonical 请求,签名基串 MUST 覆盖 operation selector; 未覆盖 selector 的签名,即使 header 本身合法也 MUST 按 http_signature_invalid 拒绝。 合同要求覆盖 selector,是为了让「换掉一个已签名请求的 selector」不能通过验签—— selector 参与业务解释、授权、幂等与审计,MUST 由发起签名的一方绑定。

一般 Station-to-Station 服务签名(/_arkret/peer/* 与其它登记的 service-to-service 面) 适用的必需项:

  • @method、@target-uri、@authority
  • arkret-operation(header Arkret-Operation,值为 exact versioned operation_id)
  • source-service-id(header Source-Service-ID,调用方 service identity)
  • destination-service-id(header Destination-Service-ID,预期接收方 service identity)
  • content-digest(条件项:请求带 body 时必需)
  • source-trust-domain、destination-trust-domain(条件项:跨 trust domain 的 transaction 必需,使一份签名不能被重放进另一个部署)
  • idempotency-key(条件项:该请求参与幂等 / replay key 时必需)

条件项的触发条件本身是合同的一部分:条件成立时该项就是必需项,漏签与漏签无条件项同罪。

其余四个场景在各自正文声明同形的覆盖集块,并同样由门禁逐项比对 canonical 合同: 单跳 signal relay 见 signal.md §4.2, Applet transaction push 见 ../extensions/applet-integration.md §7.3.1, 客户端会话 PoP 见 api-conventions.md §3.2, MIMI provider-to-provider 见 ../extensions/mimi-interop.md §5。 跨部署 KeyPackage claim 的外层服务签名是本场景的一个实例,见 ../crypto-media/device-lifecycle.md §9.2.1。

五个场景的时效窗口是同一份,见 §8.3;canonical 合同不提供逐 operation 收紧机制。 新的窗口 MUST 登记为自己的场景,MUST NOT 只写在某一页正文里。

8.2 Peer signature 与 content-digest(normative)

接收方先验证 transport signature、DID freshness 和 trust relationship,再验证内层 Event/Commit/handoff proof。transport signature 只认证请求来源与传输完整性, MUST NOT 替代任何一层内层 proof,也 MUST NOT 成为 Event authority。

带 body 的签名请求 MUST 按下列顺序处理,且顺序本身是规范性的:

  1. sender MUST 把 canonical_json(request_body) 的结果逐字节作为 exact HTTP message content, 且 MUST NOT 对其应用 Content-Encoding。
  2. Content-Digest MUST 是 RFC 9530 结构化字段,且 MUST 恰好携带一个 sha-256 member: sha-256=:base64(SHA-256(exact_http_content_bytes)):。多 member、其它算法 token 或重复 member MUST 被拒绝。
  3. receiver MUST 先对 exact HTTP content bytes 重算并校验 Content-Digest, 再严格解析并确认收到的 wire 本身就是 canonical JSON,最后验证签名 transcript。 receiver MUST NOT parse arbitrary JSON 之后只对 canonicalized value 求 digest—— 那会让非 canonical wire 通过校验。
  4. 业务层从这些已校验的 bytes 内部计算任何 Arkret request digest; header 与 body 的交叉绑定(例如 Source-Service-ID 与 body 内 source_id) MUST 在验签通过后逐项比对,任一不一致 MUST fail closed。

无 body 的请求 MUST NOT 伪造 Content-Digest member;此时 content-digest 不是适用必需项。

8.3 时效窗口与重放(normative)

created / expires 的判据由 canonical 合同的 ak.http_signature.freshness.v1 持有, 五个签名场景无一例外地共用这一份。令 now 为接收方本次校验使用的当前 Unix 秒:

  • created 与 expires MUST 同时存在且为整数 UNIX 秒;缺失或类型不合法即失败。
  • 0 < expires - created ≤ 300 秒。
  • |created - now| ≤ 30 秒,前后边界均包含。
  • now < expires;到达 expires 即过期,MUST NOT 为 expires 另加 skew 宽限。

三项 MUST 同时满足,任一不满足返回 signature_window_invalid。边界判定由 ak.vector.service.http_signature_freshness_window_boundaries.v1 钉死: 上限与两侧偏差边界取等号时接受、越界一秒即拒绝,寿命为零或为负拒绝, 到达 expires 即拒绝,replay cache evict 后的逐字节重放仍由时间检查拒绝, 缺参或非整数参数在任何比较之前失败。

v1 不设逐 operation 的窗口收紧,也没有登记这种机制:曾有两处更短的寿命上限 (单跳 signal relay 与跨站设备目录取材)只写在各自页面的正文里,没有记录过理由, 现已取消,两条链路改用本节这一份。理由是 transport 签名时效只限制这一跳被截获的 已签请求还能用多久,它不承担、也无法承担业务新鲜度与重放判据:Signal 的旧包边界由 已签 envelope 的 sent_at / expires_at、class TTL、current membership/scope 与 recipient 的去重共同执行;跨站目录取材的新鲜度由 attestation、generation、状态与 有效期判断,短寿命签名证明不了目录响应仍然新鲜。把这些职责压给一个没有依据的 transport 上限,只会在时钟偏移与排队耗时下把合法请求判死。 将来若某个面确需不同窗口,MUST 登记为自己的场景(连同 profile、正文块与投影), MUST NOT 以逐 operation 例外或某一页的散文常量存在。

  • 上限 300 秒是签名可以声明的寿命上限,不是「服务器承诺接受每份签名五分钟」: created 的 ±30 秒规则会更早拒绝一份旧签名。
  • 重放 cache 独立执行,与本节的时间检查并列。cache eviction MUST NOT 使过期签名重新有效, 也 MUST NOT 豁免 §8.1 的覆盖检查——落在窗口外的逐字节重放即便 cache 已 evict, 仍 MUST 因 created / expires 校验失败而拒绝。
  • 每次投递都是一份新的 transport signature;它与内层 immutable Event 的重签是两件事, 业务 exact retry 仍遵守其自身合同(见 api-conventions.md §6)。

8.4 DPoP 新鲜度是独立合同(normative)

RFC 9449 DPoP proof 只有 iat,没有 expires parameter,因此它 MUST NOT 继承 §8.3 的 created / expires 算法;「与联邦面同口径」不适用于 DPoP。DPoP 的判据由 canonical 合同的 ak.dpop.freshness.v1 独立持有:

  • 接受条件为 now - iat 落在 [-30, 30] 秒内,前后边界均包含。
  • jti MUST 至少保留 60 秒,且该保留时长 MUST NOT 短于 iat 接受窗口的总跨度, 否则仍可接受的 proof 会在其 jti 被遗忘后被重放。

保留期内 jti 重复 MUST fail closed,即使 iat 仍在窗口内。DPoP 与 RFC 9421 PoP 共用同一把 grant-binding key(见 api-conventions.md §3.3), 但共用密钥不合并合同:两份 profile 的数值 MUST NOT 互相代入。

9. 生成索引(informative)

本节的表格由 operation registry 生成,不承载独立义务;编号只是本页内的稳定身份,规范内容以被引用的 registry 与 schema 为准。

9.1 字段级 Schema 索引

下表是 operation registry 的生成索引,只用于确保每个 operation 的 schema ref 在正文可检索;规范字段仍以被引用 schema 为准。

9.1.1 Binding completeness index

OperationHTTPRequiredOptionalConstraints
ak.edge.applet.actor.read.resolve.v1GET /_arkret/edge/applet/actors/{actor_id}--response_schema_ref=schemas/applet-edge-operations.schema.json#/$defs/applet_actor_view
ak.edge.applet.command.transaction.v1POST /_arkret/edge/applet/transactions--request_schema_ref=schemas/applet-edge-operations.schema.json#/$defs/applet_transaction_request_body; response_schema_ref=schemas/applet-edge-operations.schema.json#/$defs/applet_transaction_outcome
ak.edge.applet.managed_actor.command.author.v1POST /_arkret/edge/applet/managed-actors/author--request_schema_ref=schemas/applet-install-authoring.schema.json#/$defs/author_request_body; response_schema_ref=schemas/applet-install-authoring.schema.json#/$defs/author_outcome
ak.edge.applet.read.describe.v1GET /_arkret/edge/applet/describe--response_schema_ref=schemas/service-describe.schema.json
ak.edge.applet.read.ping.v1GET /_arkret/edge/applet/ping--response_schema_ref=schemas/applet-edge-operations.schema.json#/$defs/applet_ping_outcome
ak.edge.applet.read.protocol_metadata.v1GET /_arkret/edge/applet/protocols/{protocol}--response_schema_ref=schemas/applet-edge-operations.schema.json#/$defs/applet_protocol_metadata
ak.edge.applet.realm.read.resolve.v1GET /_arkret/edge/applet/realms/{realm_id_or_alias}--response_schema_ref=schemas/applet-edge-operations.schema.json#/$defs/applet_realm_view
ak.edge.applet.third_party_locations.read.list.v1GET /_arkret/edge/applet/third_party/locations--response_schema_ref=schemas/applet-edge-operations.schema.json#/$defs/applet_third_party_location_list
ak.edge.applet.third_party_users.read.list.v1GET /_arkret/edge/applet/third_party/users--response_schema_ref=schemas/applet-edge-operations.schema.json#/$defs/applet_third_party_user_list
ak.edge.push.command.apply_registration.v1POST /_arkret/edge/push/registrations:apply--request_schema_ref=schemas/push-operations.schema.json#/$defs/push_registration_handoff_request_body; response_schema_ref=schemas/push-operations.schema.json#/$defs/push_registration_handoff_outcome
ak.edge.push.command.notify.v1POST /_arkret/edge/push/notify--request_schema_ref=schemas/push-operations.schema.json#/$defs/push_notify_request_body; response_schema_ref=schemas/push-operations.schema.json#/$defs/push_notify_outcome
ak.edge.push.command.register_device.v1POST /_arkret/edge/push/register-device--request_schema_ref=schemas/push-operations.schema.json#/$defs/push_register_device_request_body; response_schema_ref=schemas/push-operations.schema.json#/$defs/push_register_device_outcome
ak.edge.push.command.unregister_device.v1POST /_arkret/edge/push/unregister-device--request_schema_ref=schemas/push-operations.schema.json#/$defs/push_unregister_device_request_body
ak.find.directory.read.describe.v1GET /_arkret/find/directory/describe--response_schema_ref=schemas/service-describe.schema.json
ak.find.directory.read.resolve_realm.v1POST /_arkret/find/directory/resolve-realm--request_schema_ref=schemas/directory-operations.schema.json#/$defs/directory_resolve_realm_request_body; response_schema_ref=schemas/directory-operations.schema.json#/$defs/directory_realm_resolution_outcome
ak.find.directory.read.search_realms.v1POST /_arkret/find/directory/search-realms--request_schema_ref=schemas/directory-operations.schema.json#/$defs/directory_search_realms_request_body; response_schema_ref=schemas/directory-operations.schema.json#/$defs/directory_realm_search_outcome
ak.gate.account.command.abandon_identity_creation.v1POST /_arkret/gate/account/identity-abandonments--request_schema_ref=schemas/account-operations.schema.json#/$defs/identity_abandonment_request_body; response_schema_ref=schemas/account-operations.schema.json#/$defs/identity_abandonment_outcome
ak.gate.account.command.finalize_device_pairing.v1POST /_arkret/gate/account/device-pairing/finalizations--request_schema_ref=schemas/device-pairing.schema.json#/$defs/device_pairing_finalize_request_body; response_schema_ref=schemas/device-pairing.schema.json#/$defs/device_pairing_finalize_outcome
ak.gate.account.command.issue_did_binding_challenge.v1POST /_arkret/gate/account/did-binding-challenges--request_schema_ref=schemas/account-operations.schema.json#/$defs/did_binding_challenge_request_body; response_schema_ref=schemas/account-operations.schema.json#/$defs/did_binding_challenge_outcome
ak.gate.account.command.issue_identity_binding_challenge.v1POST /_arkret/gate/account/identity-binding-challenges--request_schema_ref=schemas/account-operations.schema.json#/$defs/identity_binding_challenge_request_body; response_schema_ref=schemas/account-operations.schema.json#/$defs/identity_binding_challenge_outcome
ak.gate.account.command.issue_recovery_completion_grant.v1POST /_arkret/gate/account/recovery-session-grants/issue--request_schema_ref=schemas/recovery-authority.schema.json#/$defs/issue_recovery_completion_grant_request; response_schema_ref=schemas/recovery-authority.schema.json#/$defs/issue_recovery_completion_grant_outcome
ak.gate.account.command.issue_session_grant.v1POST /_arkret/gate/account/session-grants--request_schema_ref=schemas/service-operation-dtos.schema.json#/$defs/SessionGrantRequestBody; response_schema_ref=schemas/service-operation-dtos.schema.json#/$defs/SessionGrantOutcome
ak.gate.account.command.logout.v1POST /_arkret/gate/account/logout--request_schema_ref=schemas/service-operation-dtos.schema.json#/$defs/AccountLogoutRequestBody; response_schema_ref=schemas/service-operation-dtos.schema.json#/$defs/AccountLogoutOutcome
ak.gate.account.command.pair_agent_key.v1POST /_arkret/gate/account/agent-key-pair--request_schema_ref=schemas/agent-operations.schema.json#/$defs/agent_key_pair_request_body; response_schema_ref=schemas/agent-operations.schema.json#/$defs/agent_key_pair_outcome
ak.gate.account.command.pair_device.v1POST /_arkret/gate/account/device-pair--request_schema_ref=schemas/agent-operations.schema.json#/$defs/account_device_pair_request_body; response_schema_ref=schemas/agent-operations.schema.json#/$defs/account_device_pair_outcome
ak.gate.account.command.refresh_session_grant.v1POST /_arkret/gate/account/session-grants/refresh--request_schema_ref=schemas/service-operation-dtos.schema.json#/$defs/SessionGrantRefreshRequestBody; response_schema_ref=schemas/service-operation-dtos.schema.json#/$defs/SessionGrantOutcome
ak.gate.account.command.register.v1POST /_arkret/gate/account/register--request_schema_ref=schemas/account-operations.schema.json#/$defs/account_register_request_body; response_schema_ref=schemas/account-operations.schema.json#/$defs/account_register_outcome
ak.gate.account.command.request_erasure.v1POST /_arkret/gate/account/erasure-requests--request_schema_ref=schemas/account-operations.schema.json#/$defs/account_request_erasure_request_body; response_schema_ref=schemas/account-operations.schema.json#/$defs/account_request_erasure_outcome
ak.gate.account.command.revoke_session.v1POST /_arkret/gate/account/session-grants/revoke--request_schema_ref=schemas/account-operations.schema.json#/$defs/session_revoke_request_body; response_schema_ref=schemas/account-operations.schema.json#/$defs/session_revoke_outcome
ak.gate.account.exchange.create_handoff.v1POST /_arkret/gate/account/authentication-handoffs--request_schema_ref=schemas/account-operations.schema.json#/$defs/account_handoff_request_body; response_schema_ref=schemas/account-operations.schema.json#/$defs/account_handoff_outcome
ak.gate.account.read.claim_device_pairing_code.v1POST /_arkret/gate/account/device-pairing/code-claims--request_schema_ref=schemas/device-pairing.schema.json#/$defs/device_pairing_code_claim_request_body; response_schema_ref=schemas/device-pairing.schema.json#/$defs/device_pairing_code_claim_outcome
ak.gate.account.read.onboarding.v1GET /_arkret/gate/account/onboarding--response_schema_ref=schemas/account-operations.schema.json#/$defs/account_onboarding_state
ak.open.agent_pairing.command.submit_runtime_key_request.v1POST /_arkret/open/agent-pairing/runtime-key-requests--request_schema_ref=schemas/agent-operations.schema.json#/$defs/agent_runtime_approval_request_body; response_schema_ref=schemas/agent-operations.schema.json#/$defs/agent_runtime_approval_outcome
ak.open.agent_pairing.read.resolve.v1POST /_arkret/open/agent-pairing/resolve--request_schema_ref=schemas/agent-operations.schema.json#/$defs/agent_pairing_resolve_request_body; response_schema_ref=schemas/agent-operations.schema.json#/$defs/agent_pairing_bootstrap
ak.open.agent_pairing.read.runtime_key_request_status.v1POST /_arkret/open/agent-pairing/runtime-key-requests/status--request_schema_ref=schemas/agent-operations.schema.json#/$defs/agent_runtime_approval_status_request_body; response_schema_ref=schemas/agent-operations.schema.json#/$defs/agent_runtime_approval_status_outcome
ak.open.device_pairing.command.stage.v1POST /_arkret/open/device-pairing/requests--request_schema_ref=schemas/device-pairing.schema.json#/$defs/device_pairing_stage_request_body; response_schema_ref=schemas/device-pairing.schema.json#/$defs/device_pairing_stage_outcome
ak.open.device_pairing.read.resolve.v1POST /_arkret/open/device-pairing/resolve--request_schema_ref=schemas/device-pairing.schema.json#/$defs/device_pairing_resolve_request_body; response_schema_ref=schemas/device-pairing.schema.json#/$defs/device_pairing_bootstrap
ak.open.device_pairing.read.status.v1POST /_arkret/open/device-pairing/requests/status--request_schema_ref=schemas/device-pairing.schema.json#/$defs/device_pairing_status_request_body; response_schema_ref=schemas/device-pairing.schema.json#/$defs/device_pairing_status_outcome
ak.open.identity.read.resolution.v1GET /_arkret/open/principals/{principal_id}/resolution--response_schema_ref=schemas/identity-resolution.schema.json#/$defs/public_principal_resolution
ak.open.invite_locator.read.resolve.v1POST /_arkret/open/invite-locators/resolve--request_schema_ref=schemas/principal-locator.schema.json#/$defs/principal_locator_resolve_request_body; response_schema_ref=schemas/principal-locator.schema.json
ak.open.mimi.command.notify.v1POST /_arkret/open/mimi/strands/{strand_id}/notify--request_schema_ref=schemas/mimi-operations.schema.json#/$defs/mimi_notify_request_body; response_schema_ref=schemas/mimi-operations.schema.json#/$defs/mimi_notify_outcome
ak.open.mimi.command.proxy_download.v1POST /_arkret/open/mimi/proxy-download--request_schema_ref=schemas/mimi-operations.schema.json#/$defs/mimi_proxy_download_request_body; response_schema_ref=schemas/mimi-operations.schema.json#/$defs/mimi_proxy_download_outcome
ak.open.mimi.command.report_abuse.v1POST /_arkret/open/mimi/report-abuse--request_schema_ref=schemas/mimi-operations.schema.json#/$defs/mimi_report_abuse_request_body; response_schema_ref=schemas/mimi-operations.schema.json#/$defs/mimi_report_abuse_outcome
ak.open.mimi.command.request_consent.v1POST /_arkret/open/mimi/consent/request--request_schema_ref=schemas/mimi-operations.schema.json#/$defs/mimi_request_consent_request_body; response_schema_ref=schemas/mimi-operations.schema.json#/$defs/mimi_request_consent_outcome
ak.open.mimi.command.submit_message.v1POST /_arkret/open/mimi/strands/{strand_id}/messages--request_schema_ref=schemas/mimi-operations.schema.json#/$defs/mimi_submit_message_request_body; response_schema_ref=schemas/mimi-operations.schema.json#/$defs/mimi_submit_message_outcome
ak.open.mimi.command.update_consent.v1POST /_arkret/open/mimi/consent/update--request_schema_ref=schemas/mimi-operations.schema.json#/$defs/mimi_update_consent_request_body; response_schema_ref=schemas/mimi-operations.schema.json#/$defs/mimi_update_consent_outcome
ak.open.mimi.command.update_room.v1POST /_arkret/open/mimi/strands/{strand_id}/update--request_schema_ref=schemas/mimi-operations.schema.json#/$defs/mimi_room_update_request_body; response_schema_ref=schemas/mimi-operations.schema.json#/$defs/mimi_room_update_outcome
ak.open.mimi.exchange.request_key_material.v1POST /_arkret/open/mimi/key-material--request_schema_ref=schemas/mimi-operations.schema.json#/$defs/mimi_key_material_request_body; response_schema_ref=schemas/mimi-operations.schema.json#/$defs/mimi_key_material_outcome
ak.open.mimi.read.identifiers.v1POST /_arkret/open/mimi/identifiers/query--request_schema_ref=schemas/mimi-operations.schema.json#/$defs/mimi_identifier_query_request_body; response_schema_ref=schemas/mimi-operations.schema.json#/$defs/mimi_identifier_query_outcome
ak.open.mimi.read.provider_directory.v1GET /_arkret/open/mimi/provider-directory--response_schema_ref=schemas/mimi-interop.schema.json
ak.open.realm_authority.read.bundle.v1POST /_arkret/open/realm-authority/bundle--request_schema_ref=schemas/authority-commit-operations.schema.json#/$defs/authority_bundle_request; response_schema_ref=schemas/realm-authority-bundle.schema.json
ak.open.service.read.resolution.v1GET /_arkret/open/services/{service_id}/resolution--response_schema_ref=schemas/identity-resolution.schema.json#/$defs/authenticated_service_resolution
ak.open.third_party_invite.command.activate.v1POST /_arkret/open/third-party-invites/activate--request_schema_ref=schemas/invite.schema.json#/$defs/third_party_invite_activation_request_body; response_schema_ref=schemas/invite.schema.json#/$defs/third_party_invite_activation_outcome
ak.open.third_party_invite.command.present_token.v1POST /_arkret/open/third-party-invites/present--request_schema_ref=schemas/invite.schema.json#/$defs/third_party_invite_present_request_body; response_schema_ref=schemas/invite.schema.json#/$defs/third_party_invite_present_outcome
ak.open.third_party_invite.command.provision.v1POST /_arkret/open/third-party-invites/provision--request_schema_ref=schemas/invite.schema.json#/$defs/third_party_invite_provision_request_body; response_schema_ref=schemas/invite.schema.json#/$defs/third_party_invite_provision_outcome
ak.open.third_party_invite.read.provisioning_status.v1POST /_arkret/open/third-party-invites/status--request_schema_ref=schemas/invite.schema.json#/$defs/third_party_invite_provisioning_status_request_body; response_schema_ref=schemas/invite.schema.json#/$defs/third_party_invite_provisioning_status_outcome
ak.peer.account_status.command.submit.v1POST /_arkret/peer/account-status--request_schema_ref=schemas/account-operations.schema.json#/$defs/account_status_publication_request_body; response_schema_ref=schemas/account-operations.schema.json#/$defs/account_status_publication_outcome
ak.peer.account_status.read.resolve.v1POST /_arkret/peer/account-status/resolve--request_schema_ref=schemas/account-operations.schema.json#/$defs/account_status_resolve_request_body; response_schema_ref=schemas/account-operations.schema.json#/$defs/account_status_resolve_outcome
ak.peer.committed_event.read.scan.v1POST /_arkret/peer/streams/scan--request_schema_ref=schemas/authority-commit-operations.schema.json#/$defs/stream_scan_request; response_schema_ref=schemas/authority-commit-operations.schema.json#/$defs/peer_stream_scan_outcome
ak.peer.contacts.command.submit.v1POST /_arkret/peer/contacts--request_schema_ref=schemas/contact-operations.schema.json#/$defs/peer_contact_submit_request; response_schema_ref=schemas/contact-operations.schema.json#/$defs/peer_contact_submit_outcome
ak.peer.erasure_receipt.command.submit.v1POST /_arkret/peer/erasure-receipts--request_schema_ref=schemas/erasure-receipt-operations.schema.json#/$defs/erasure_receipt_submit_request_body; response_schema_ref=schemas/erasure-receipt-operations.schema.json#/$defs/erasure_receipt_submit_outcome
ak.peer.erasure_receipt.resource.get.v1GET /_arkret/peer/erasure-receipts/{receipt_id}--response_schema_ref=schemas/erasure-receipt-operations.schema.json#/$defs/erasure_receipt_resource
ak.peer.events.command.submit.v1POST /_arkret/peer/events--request_schema_ref=schemas/authority-commit-operations.schema.json#/$defs/peer_submit_request; response_schema_ref=schemas/authority-commit-operations.schema.json#/$defs/peer_submit_outcome
ak.peer.invites.command.submit.v1POST /_arkret/peer/invites--request_schema_ref=schemas/invite-delivery-request.schema.json; response_schema_ref=schemas/invite-delivery-request.schema.json#/$defs/invite_delivery_outcome
ak.peer.keys.keypackages.command.claim.v1POST /_arkret/peer/keys/keypackages/claim--request_schema_ref=schemas/keypackage-operations.schema.json#/$defs/keypackages_claim_request_body; response_schema_ref=schemas/keypackage-operations.schema.json#/$defs/peer_keypackages_claim_command_outcome
ak.peer.keys.keypackages.read.claim.v1POST /_arkret/peer/keys/keypackages/claims/query--request_schema_ref=schemas/keypackage-operations.schema.json#/$defs/peer_keypackages_claim_query_request_body; response_schema_ref=schemas/keypackage-operations.schema.json#/$defs/peer_keypackages_claim_query_outcome
ak.peer.keys.read.lookup.v1POST /_arkret/peer/keys/query--request_schema_ref=schemas/keys-operations.schema.json#/$defs/peer_keys_query_request_body; response_schema_ref=schemas/keys-operations.schema.json#/$defs/peer_keys_query_outcome
ak.peer.mls.command.attest_add.v1POST /_arkret/peer/mls/add-authority-attestations--request_schema_ref=schemas/mls-roster-authority.schema.json#/$defs/attest_add_request; response_schema_ref=schemas/mls-roster-authority.schema.json#/$defs/attest_add_outcome
ak.peer.mls.read.group_state_material.v1POST /_arkret/peer/mls/group-state-material--request_schema_ref=schemas/service-operation-dtos.schema.json#/$defs/MlsGroupStateMaterialRequestBody; response_schema_ref=schemas/service-operation-dtos.schema.json#/$defs/MlsGroupStateMaterialOutcome
ak.peer.mls.read.roster_authority.v1POST /_arkret/peer/mls/roster-authority/query--request_schema_ref=schemas/mls-roster-authority.schema.json#/$defs/roster_read_request; response_schema_ref=schemas/mls-roster-authority.schema.json#/$defs/roster_read_outcome
ak.peer.realm_authority.command.handoff.v1POST /_arkret/peer/realm-authority/handoff--request_schema_ref=schemas/authority-commit-operations.schema.json#/$defs/handoff_request; response_schema_ref=schemas/realm-authority-handoff.schema.json
ak.peer.realm_join.read.bootstrap.v1POST /_arkret/peer/realm-joins/bootstrap--request_schema_ref=schemas/realm-join-intake.schema.json#/$defs/peer_bootstrap_request_body; response_schema_ref=schemas/realm-join-intake.schema.json#/$defs/peer_bootstrap_outcome
ak.peer.realm_join.read.preview.v1POST /_arkret/peer/realm-joins/preview--request_schema_ref=schemas/realm-join-intake.schema.json#/$defs/peer_preview_request_body; response_schema_ref=schemas/realm-join-intake.schema.json#/$defs/peer_preview_outcome
ak.peer.signal.command.relay.v1POST /_arkret/peer/signal--request_schema_ref=schemas/signal-relay.schema.json
ak.root.identity.command.submit_did_operation.v1POST /_arkret/root/identity/submit-did-operation--request_schema_ref=schemas/service-operation-dtos.schema.json#/$defs/DidOperationSubmitRequestBody; response_schema_ref=schemas/service-operation-dtos.schema.json#/$defs/DidOperationSubmitOutcome
ak.root.identity.document.resource.get.v1GET /_arkret/root/identity/document--response_schema_ref=schemas/service-operation-dtos.schema.json#/$defs/IdentityDocumentView
ak.root.identity.log.read.list.v1GET /_arkret/root/identity/log--response_schema_ref=schemas/service-operation-dtos.schema.json#/$defs/IdentityLogListOutcome
ak.root.identity.organization_registration.command.ensure.v1POST /_arkret/root/identity/organization-registrations:ensure--request_schema_ref=schemas/service-operation-dtos.schema.json#/$defs/OrganizationRegistrationEnsureRequestBody; response_schema_ref=schemas/service-operation-dtos.schema.json#/$defs/OrganizationRegistrationOutcome
ak.root.identity.organization_registration.command.prepare.v1POST /_arkret/root/identity/organization-registrations:prepare--request_schema_ref=schemas/service-operation-dtos.schema.json#/$defs/OrganizationRegistrationChallengeRequestBody; response_schema_ref=schemas/service-operation-dtos.schema.json#/$defs/OrganizationRegistrationChallenge
ak.root.identity.organization_registration.command.refresh.v1POST /_arkret/root/identity/organization-registrations:refresh--request_schema_ref=schemas/service-operation-dtos.schema.json#/$defs/OrganizationRegistrationRefreshRequestBody; response_schema_ref=schemas/service-operation-dtos.schema.json#/$defs/OrganizationRegistrationOutcome
ak.root.identity.organization_registration.command.revoke.v1POST /_arkret/root/identity/organization-registrations:revoke--request_schema_ref=schemas/service-operation-dtos.schema.json#/$defs/OrganizationRegistrationRevokeRequestBody; response_schema_ref=schemas/service-operation-dtos.schema.json#/$defs/OrganizationRegistrationOutcome
ak.root.identity.organization_registration.resource.get.v1GET /_arkret/root/identity/organization-registrations--response_schema_ref=schemas/service-operation-dtos.schema.json#/$defs/OrganizationRegistrationOutcome
ak.root.identity.read.resolve.v1POST /_arkret/root/identity/resolve--request_schema_ref=schemas/service-operation-dtos.schema.json#/$defs/IdentityResolveRequestBody; response_schema_ref=schemas/service-operation-dtos.schema.json#/$defs/IdentityResolveOutcome
ak.root.identity.receipts.read.list.v1GET /_arkret/root/identity/receipts--response_schema_ref=schemas/service-operation-dtos.schema.json#/$defs/IdentityReceiptListOutcome
ak.root.identity.recovery_policy.command.publish.v1POST /_arkret/root/identity/recovery-policy--request_schema_ref=schemas/recovery-policy.schema.json#/$defs/recovery_policy_publish_request; response_schema_ref=schemas/recovery-policy.schema.json#/$defs/recovery_policy_publish_outcome
ak.root.identity.recovery_policy.resource.get.v1GET /_arkret/root/identity/recovery-policy--response_schema_ref=schemas/recovery-policy.schema.json#/$defs/recovery_policy_active_outcome
ak.root.identity.recovery_session.command.create.v1POST /_arkret/root/identity/recovery-sessions--request_schema_ref=schemas/recovery-session.schema.json#/$defs/recovery_session_create_request_body; response_schema_ref=schemas/recovery-session.schema.json#/$defs/recovery_session_state
ak.root.identity.recovery_session.command.submit_proof.v1POST /_arkret/root/identity/recovery-sessions/{recovery_session_id}/proofs--request_schema_ref=schemas/recovery-session.schema.json#/$defs/recovery_session_proof_submit_request_body; response_schema_ref=schemas/recovery-session.schema.json#/$defs/recovery_session_proof_submit_outcome
ak.root.identity.recovery_session.resource.get.v1GET /_arkret/root/identity/recovery-sessions/{recovery_session_id}--response_schema_ref=schemas/recovery-session.schema.json#/$defs/recovery_session_state
ak.root.identity.registry.read.describe.v1GET /_arkret/root/identity/describe--response_schema_ref=schemas/service-describe.schema.json
ak.root.identity.service_registration.command.ensure.v1POST /_arkret/root/identity/service-registrations:ensure--request_schema_ref=schemas/service-operation-dtos.schema.json#/$defs/ServiceRegistrationEnsureRequestBody; response_schema_ref=schemas/service-operation-dtos.schema.json#/$defs/ServiceRegistrationOutcome
ak.root.identity.service_registration.resource.get.v1GET /_arkret/root/identity/service-registrations--response_schema_ref=schemas/service-operation-dtos.schema.json#/$defs/ServiceRegistrationOutcome
ak.self.account.command.revoke_cursor.v1POST /_arkret/self/account/cursor/revoke--request_schema_ref=schemas/service-operation-dtos.schema.json#/$defs/AccountCursorRevokeRequestBody; response_schema_ref=schemas/service-operation-dtos.schema.json#/$defs/AccountCursorRevokeOutcome
ak.self.account.command.update_profile.v1POST /_arkret/self/account/profile--request_schema_ref=schemas/account-operations.schema.json#/$defs/account_update_profile_request_body; response_schema_ref=schemas/account-operations.schema.json#/$defs/account_update_profile_outcome
ak.self.account.read.describe.v1GET /_arkret/self/account/describe--response_schema_ref=schemas/service-describe.schema.json
ak.self.account.read.viewer.v1GET /_arkret/self/account/viewer--response_schema_ref=schemas/account-operations.schema.json#/$defs/account_view
ak.self.account.stream.subscribe.v1GET /_arkret/self/account/subscribe--response_schema_ref=schemas/account-subscribe-frame.schema.json
ak.self.account_data.read.list.v1GET /_arkret/self/account_data--response_schema_ref=schemas/account-data-operations.schema.json#/$defs/account_data_list
ak.self.account_data.resource.delete.v1DELETE /_arkret/self/account_data/{account_data_key}--request_schema_ref=schemas/account-data-operations.schema.json#/$defs/account_data_delete_request_body; response_schema_ref=schemas/account-data-operations.schema.json#/$defs/account_data_delete_outcome
ak.self.account_data.resource.get.v1GET /_arkret/self/account_data/{account_data_key}--response_schema_ref=schemas/account-data-operations.schema.json#/$defs/account_data_entry
ak.self.account_data.resource.replace.v1PUT /_arkret/self/account_data/{account_data_key}--request_schema_ref=schemas/account-data-operations.schema.json#/$defs/account_data_replace_request_body; response_schema_ref=schemas/account-data-operations.schema.json#/$defs/account_data_entry
ak.self.actor_private_events.command.submit.v1POST /_arkret/self/actor-private-events--request_schema_ref=schemas/service-operation-dtos.schema.json#/$defs/ActorPrivateEventSubmitRequestBody; response_schema_ref=schemas/service-operation-dtos.schema.json#/$defs/ActorPrivateEventSubmitOutcome
ak.self.actor_profile.read.resolve.v1POST /_arkret/self/actor-profiles/query--request_schema_ref=schemas/actor-profile-operations.schema.json#/$defs/resolve_request; response_schema_ref=schemas/actor-profile-operations.schema.json#/$defs/resolve_outcome
ak.self.agent.command.deactivate.v1POST /_arkret/self/agents/{agent_id}/deactivate--request_schema_ref=schemas/agent-operations.schema.json#/$defs/agent_deactivate_request_body; response_schema_ref=schemas/agent-operations.schema.json#/$defs/agent_lifecycle_state
ak.self.agent.command.pause.v1POST /_arkret/self/agents/{agent_id}/pause--request_schema_ref=schemas/agent-operations.schema.json#/$defs/agent_pause_request_body; response_schema_ref=schemas/agent-operations.schema.json#/$defs/agent_lifecycle_state
ak.self.agent.command.provision.v1POST /_arkret/self/agents--request_schema_ref=schemas/agent-operations.schema.json#/$defs/agent_provision_request_body; response_schema_ref=schemas/agent-operations.schema.json#/$defs/agent_provision_outcome
ak.self.agent.command.renew_pairing.v1POST /_arkret/self/agents/{agent_id}/renew-pairing--request_schema_ref=schemas/agent-operations.schema.json#/$defs/agent_renew_pairing_request_body; response_schema_ref=schemas/agent-operations.schema.json#/$defs/agent_renew_pairing_outcome
ak.self.agent.command.resume.v1POST /_arkret/self/agents/{agent_id}/resume--request_schema_ref=schemas/agent-operations.schema.json#/$defs/agent_resume_request_body; response_schema_ref=schemas/agent-operations.schema.json#/$defs/agent_lifecycle_state
ak.self.agent.participation.resource.get.v1GET /_arkret/self/agents/{agent_id}/participation--response_schema_ref=schemas/agent-operations.schema.json#/$defs/agent_participation_outcome
ak.self.agent.participation.resource.replace.v1PUT /_arkret/self/agents/{agent_id}/participation--request_schema_ref=schemas/principal-operations.schema.json#/$defs/participation_replace_request; response_schema_ref=schemas/agent-operations.schema.json#/$defs/agent_participation_outcome
ak.self.agent.read.list.v1GET /_arkret/self/agents--response_schema_ref=schemas/agent-operations.schema.json#/$defs/agent_list
ak.self.agent.resource.get.v1GET /_arkret/self/agents/{agent_id}--response_schema_ref=schemas/agent-operations.schema.json#/$defs/agent_view
ak.self.agent.sidecar.command.ensure.v1POST /_arkret/self/agent-sidecars:ensure--request_schema_ref=schemas/principal-operations.schema.json#/$defs/sidecar_ensure_request; response_schema_ref=schemas/principal-operations.schema.json#/$defs/sidecar_ensure_outcome
ak.self.agent.sidecar.read.list.v1GET /_arkret/self/agent-sidecars--response_schema_ref=schemas/agent-operations.schema.json#/$defs/agent_sidecar_list
ak.self.agent.sidecar.resource.get.v1GET /_arkret/self/agent-sidecars/{sidecar_id}--response_schema_ref=schemas/agent-operations.schema.json#/$defs/agent_sidecar_view
ak.self.applet.authority.read.material.v1POST /_arkret/self/applets/{applet_id}/authority/material--request_schema_ref=schemas/applet-authority-material.schema.json#/$defs/request; response_schema_ref=schemas/applet-authority-material.schema.json#/$defs/outcome
ak.self.applet.bot.command.preview.v1POST /_arkret/self/applets/{applet_id}/bots/provision/preview--request_schema_ref=schemas/applet-bot-operations.schema.json#/$defs/bot_preview_request_body; response_schema_ref=schemas/applet-bot-operations.schema.json#/$defs/bot_preview_outcome
ak.self.applet.bot.command.provision.v1POST /_arkret/self/applets/{applet_id}/bots/provision--request_schema_ref=schemas/applet-bot-operations.schema.json#/$defs/bot_actor_provision_request_body; response_schema_ref=schemas/applet-bot-operations.schema.json#/$defs/bot_actor_provision_outcome
ak.self.applet.command.install.v1POST /_arkret/self/applets/install--request_schema_ref=schemas/applet-install-operations.schema.json#/$defs/applet_install_request_body; response_schema_ref=schemas/applet-install-operations.schema.json#/$defs/applet_install_outcome
ak.self.applet.command.revoke.v1POST /_arkret/self/applets/{applet_id}/revoke--request_schema_ref=schemas/applet-install-operations.schema.json#/$defs/applet_revoke_request_body; response_schema_ref=schemas/applet-install-operations.schema.json#/$defs/applet_revoke_outcome
ak.self.applet.ghost.command.preview.v1POST /_arkret/self/applets/{applet_id}/ghosts/provision/preview--request_schema_ref=schemas/applet-ghost-operations.schema.json#/$defs/ghost_preview_request_body; response_schema_ref=schemas/applet-ghost-operations.schema.json#/$defs/ghost_preview_outcome
ak.self.applet.ghost.command.provision.v1POST /_arkret/self/applets/{applet_id}/ghosts/provision--request_schema_ref=schemas/applet-ghost-operations.schema.json#/$defs/ghost_actor_provision_request_body; response_schema_ref=schemas/applet-ghost-operations.schema.json#/$defs/ghost_actor_provision_outcome
ak.self.applet.install.command.preview.v1POST /_arkret/self/applets/install/preview--request_schema_ref=schemas/applet-install-operations.schema.json#/$defs/applet_install_preview_request_body; response_schema_ref=schemas/applet-install-authoring.schema.json#/$defs/install_preview_outcome
ak.self.applet.revoke.command.preview.v1POST /_arkret/self/applets/{applet_id}/revoke/preview--request_schema_ref=schemas/applet-install-operations.schema.json#/$defs/applet_revoke_preview_request_body; response_schema_ref=schemas/applet-install-operations.schema.json#/$defs/applet_revoke_preview_outcome
ak.self.authz.grants.read.effective.v1GET /_arkret/self/authz/effective-grants--response_schema_ref=schemas/service-operation-dtos.schema.json#/$defs/GrantList
ak.self.authz.invites.read.list.v1GET /_arkret/self/authz/invites--response_schema_ref=schemas/authz-operations.schema.json#/$defs/authz_invite_list
ak.self.authz.read.check.v1POST /_arkret/self/authz/check--request_schema_ref=schemas/service-operation-dtos.schema.json#/$defs/AuthzCheckRequestBody; response_schema_ref=schemas/service-operation-dtos.schema.json#/$defs/AuthzCheckOutcome
ak.self.blob.command.presign.v1POST /_arkret/self/blob/presign--request_schema_ref=schemas/service-operation-dtos.schema.json#/$defs/BlobPresignRequestBody; response_schema_ref=schemas/service-operation-dtos.schema.json#/$defs/BlobPresignOutcome
ak.self.blob.resource.get.v1GET /_arkret/self/blob/get--registry-declared non-JSON or shared binding
ak.self.blob.resource.head.v1HEAD /_arkret/self/blob/get--registry-declared non-JSON or shared binding
ak.self.blob.upload.create.v1POST /_arkret/self/blob/upload--request_schema_ref=schemas/blob-operations.schema.json#/$defs/blob_upload_request_body; response_schema_ref=schemas/blob-operations.schema.json#/$defs/blob_upload_outcome
ak.self.call.media.exchange.issue_token.v1POST /_arkret/self/rtc/token--request_schema_ref=schemas/service-operation-dtos.schema.json#/$defs/CallMediaTokenExchangeRequestBody; response_schema_ref=schemas/service-operation-dtos.schema.json#/$defs/CallMediaTokenExchangeOutcome
ak.self.circle.command.create.v1POST /_arkret/self/circles--request_schema_ref=schemas/circle-operations.schema.json#/$defs/circle_create_request_body; response_schema_ref=schemas/circle-operations.schema.json#/$defs/circle_view
ak.self.circle.command.rotate_scope.v1POST /_arkret/self/circles/{circle_id}/scope-rotate--response_schema_ref=schemas/circle-operations.schema.json#/$defs/circle_scope_rotate_outcome
ak.self.circle.member.command.add.v1POST /_arkret/self/circles/{circle_id}/members--request_schema_ref=schemas/circle-operations.schema.json#/$defs/circle_member_request_body; response_schema_ref=schemas/circle-operations.schema.json#/$defs/circle_membership_outcome
ak.self.circle.member.resource.delete.v1DELETE /_arkret/self/circles/{circle_id}/members/{actor_id}--request_schema_ref=schemas/circle-operations.schema.json#/$defs/circle_member_delete_request_body; response_schema_ref=schemas/circle-operations.schema.json#/$defs/circle_membership_outcome
ak.self.circle.read.list.v1GET /_arkret/self/circles--response_schema_ref=schemas/circle-operations.schema.json#/$defs/circle_list
ak.self.circle.resource.get.v1GET /_arkret/self/circles/{circle_id}--response_schema_ref=schemas/circle-operations.schema.json#/$defs/circle_read_view
ak.self.committed_event.read.scan.v1POST /_arkret/self/streams/scan--request_schema_ref=schemas/authority-commit-operations.schema.json#/$defs/stream_scan_request; response_schema_ref=schemas/authority-commit-operations.schema.json#/$defs/stream_scan_outcome
ak.self.committed_event.resource.get.v1GET /_arkret/self/committed-events/{event_id}--response_schema_ref=schemas/service-operation-dtos.schema.json#/$defs/CommittedEventView
ak.self.committed_event.stream.subscribe.v1GET /_arkret/self/committed-events/subscribe--response_schema_ref=schemas/committed-event-subscribe-frame.schema.json
ak.self.consent.command.grant.v1POST /_arkret/self/consent/results/grant--request_schema_ref=schemas/consent-operations.schema.json#/$defs/consent_grant_request_body; response_schema_ref=schemas/consent-operations.schema.json#/$defs/consent_view
ak.self.consent.command.request.v1POST /_arkret/self/consent/request--request_schema_ref=schemas/consent-operations.schema.json#/$defs/consent_request_request_body; response_schema_ref=schemas/consent-operations.schema.json#/$defs/consent_request_outcome
ak.self.consent.command.revoke.v1POST /_arkret/self/consent/results/revoke--request_schema_ref=schemas/consent-operations.schema.json#/$defs/consent_revoke_request_body; response_schema_ref=schemas/consent-operations.schema.json#/$defs/consent_view
ak.self.consent.read.list.v1GET /_arkret/self/consent/results--response_schema_ref=schemas/consent-operations.schema.json#/$defs/consent_list
ak.self.consent.resource.get.v1GET /_arkret/self/consent/result--response_schema_ref=schemas/consent-operations.schema.json#/$defs/consent_view
ak.self.contact.command.checkpoint.v1POST /_arkret/self/contacts/continuity-checkpoint--request_schema_ref=schemas/contact-operations.schema.json#/$defs/contact_continuity_checkpoint_request_body; response_schema_ref=schemas/contact-operations.schema.json#/$defs/contact_continuity_checkpoint_outcome
ak.self.contact.command.reject.v1POST /_arkret/self/contacts/reject--request_schema_ref=schemas/contact-operations.schema.json#/$defs/contact_reject_request; response_schema_ref=schemas/contact-operations.schema.json#/$defs/contact_reject_outcome
ak.self.contact.command.request.v1POST /_arkret/self/contacts/request--request_schema_ref=schemas/contact-operations.schema.json#/$defs/contact_operation_request; response_schema_ref=schemas/contact-operations.schema.json#/$defs/contact_request_outcome
ak.self.contact.command.respond.v1POST /_arkret/self/contacts/respond--request_schema_ref=schemas/contact-operations.schema.json#/$defs/contact_respond_request; response_schema_ref=schemas/contact-operations.schema.json#/$defs/contact_respond_outcome
ak.self.contact.command.scope_update.v1POST /_arkret/self/contacts/scope-update--request_schema_ref=schemas/contact-operations.schema.json#/$defs/contact_scope_update_request; response_schema_ref=schemas/contact-operations.schema.json#/$defs/contact_scope_update_outcome
ak.self.contact.command.tombstone.v1POST /_arkret/self/contacts/tombstone--request_schema_ref=schemas/contact-operations.schema.json#/$defs/contact_tombstone_request; response_schema_ref=schemas/contact-operations.schema.json#/$defs/contact_tombstone_outcome
ak.self.contact.read.list.v1GET /_arkret/self/contacts--response_schema_ref=schemas/contact-operations.schema.json#/$defs/contact_list
ak.self.current_principal.read.resolve.v1POST /_arkret/self/account/current-principal--request_schema_ref=schemas/identity-resolution.schema.json#/$defs/current_principal_request_body; response_schema_ref=schemas/identity-resolution.schema.json#/$defs/current_principal_outcome
ak.self.current_results.read.exact.v1POST /_arkret/self/current-results/exact--request_schema_ref=schemas/exact-current-results-read.schema.json#/$defs/exact_current_results_read_request; response_schema_ref=schemas/exact-current-results-read.schema.json#/$defs/exact_current_results_read_outcome
ak.self.device_messages.command.ack.v1POST /_arkret/self/device_messages/ack--request_schema_ref=schemas/service-operation-dtos.schema.json#/$defs/DeviceMessagesAckRequestBody; response_schema_ref=schemas/service-operation-dtos.schema.json#/$defs/DeviceMessagesAckOutcome
ak.self.device_messages.command.send.v1POST /_arkret/self/device_messages--request_schema_ref=schemas/service-operation-dtos.schema.json#/$defs/DeviceMessagesSendRequestBody; response_schema_ref=schemas/service-operation-dtos.schema.json#/$defs/DeviceMessagesSendOutcome
ak.self.device_messages.read.list.v1GET /_arkret/self/device_messages--response_schema_ref=schemas/service-operation-dtos.schema.json#/$defs/DeviceMessagesGetOutcome
ak.self.direct_conversation.read.resolve.v1POST /_arkret/self/direct-conversations/resolve--request_schema_ref=schemas/direct-conversation-operations.schema.json#/$defs/direct_conversation_resolve_request; response_schema_ref=schemas/direct-conversation-operations.schema.json#/$defs/direct_conversation_resolve_outcome
ak.self.events.command.submit.v1POST /_arkret/self/events--request_schema_ref=schemas/authority-commit-operations.schema.json#/$defs/self_submit_request; response_schema_ref=schemas/authority-commit-operations.schema.json#/$defs/self_submit_outcome
ak.self.events.read.delivery_status.v1QUERY /_arkret/self/events/delivery-status--request_schema_ref=schemas/service-operation-dtos.schema.json#/$defs/EventDeliveryStatusRequestBody; response_schema_ref=schemas/service-operation-dtos.schema.json#/$defs/EventDeliveryStatusOutcome
ak.self.identity.read.resolution_audit.v1POST /_arkret/self/identity/resolution-audit/query--request_schema_ref=schemas/identity-resolution.schema.json#/$defs/principal_resolution_audit_request; response_schema_ref=schemas/identity-resolution.schema.json#/$defs/principal_resolution_audit_evidence
ak.self.invite_locator.command.issue.v1POST /_arkret/self/invite-locators--request_schema_ref=schemas/principal-locator.schema.json#/$defs/invite_locator_issue_request_body; response_schema_ref=schemas/principal-locator.schema.json#/$defs/invite_locator_issue_outcome
ak.self.invite_locator.command.revoke.v1POST /_arkret/self/invite-locators/revoke--request_schema_ref=schemas/principal-locator.schema.json#/$defs/invite_locator_revoke_request_body; response_schema_ref=schemas/principal-locator.schema.json#/$defs/invite_locator_revoke_outcome
ak.self.invite_locator.command.rotate.v1POST /_arkret/self/invite-locators/rotate--request_schema_ref=schemas/principal-locator.schema.json#/$defs/invite_locator_rotate_request_body; response_schema_ref=schemas/principal-locator.schema.json#/$defs/invite_locator_issue_outcome
ak.self.invite_receive_policy.resource.get.v1GET /_arkret/self/invite-receive-policy--response_schema_ref=schemas/invite-receive-policy.schema.json
ak.self.invite_receive_policy.resource.replace.v1PUT /_arkret/self/invite-receive-policy--request_schema_ref=schemas/invite-receive-policy.schema.json; response_schema_ref=schemas/invite-receive-policy.schema.json
ak.self.invites.command.dispatch.v1POST /_arkret/self/invites/dispatch--request_schema_ref=schemas/invite-delivery-request.schema.json#/$defs/self_invite_dispatch_request_body; response_schema_ref=schemas/invite-delivery-request.schema.json#/$defs/invite_delivery_outcome
ak.self.keys.backups.command.issue_delete_challenge.v1POST /_arkret/self/keys/backups/{backup_id}/delete-challenge--request_schema_ref=schemas/keys-operations.schema.json#/$defs/keys_backups_issue_delete_challenge_request_body; response_schema_ref=schemas/keys-operations.schema.json#/$defs/keys_backups_delete_challenge
ak.self.keys.backups.command.issue_unlock_challenge.v1POST /_arkret/self/keys/backups/{backup_id}/unlock-challenge--request_schema_ref=schemas/keys-operations.schema.json#/$defs/keys_backups_issue_unlock_challenge_request_body; response_schema_ref=schemas/keys-operations.schema.json#/$defs/keys_backups_unlock_challenge
ak.self.keys.backups.command.unlock.v1POST /_arkret/self/keys/backups/{backup_id}/unlock--request_schema_ref=schemas/keys-operations.schema.json#/$defs/keys_backups_unlock_request_body; response_schema_ref=schemas/key-backup.schema.json
ak.self.keys.backups.read.list.v1GET /_arkret/self/keys/backups--response_schema_ref=schemas/keys-operations.schema.json#/$defs/keys_backups_list
ak.self.keys.backups.resource.delete.v1DELETE /_arkret/self/keys/backups/{backup_id}--request_schema_ref=schemas/keys-operations.schema.json#/$defs/keys_backups_delete_request_body
ak.self.keys.backups.resource.replace.v1PUT /_arkret/self/keys/backups/{backup_id}--request_schema_ref=schemas/key-backup.schema.json; response_schema_ref=schemas/keys-operations.schema.json#/$defs/keys_backups_replace_outcome
ak.self.keys.command.claim.v1POST /_arkret/self/keys/claim--request_schema_ref=schemas/keys-operations.schema.json#/$defs/keys_claim_request_body; response_schema_ref=schemas/keys-operations.schema.json#/$defs/keys_claim_outcome
ak.self.keys.keypackages.command.claim.v1POST /_arkret/self/keys/keypackages/claim--request_schema_ref=schemas/keypackage-operations.schema.json#/$defs/keypackages_claim_request_body; response_schema_ref=schemas/keypackage-operations.schema.json#/$defs/keypackages_claim_outcome
ak.self.keys.keypackages.command.consume.v1POST /_arkret/self/keys/keypackages/consume--request_schema_ref=schemas/keypackage-operations.schema.json#/$defs/keypackages_consume_request_body; response_schema_ref=schemas/keypackage-operations.schema.json#/$defs/keypackages_consume_outcome
ak.self.keys.keypackages.command.revoke.v1POST /_arkret/self/keys/keypackages/revoke--request_schema_ref=schemas/keypackage-operations.schema.json#/$defs/keypackages_revoke_request_body; response_schema_ref=schemas/keypackage-operations.schema.json#/$defs/keypackages_revoke_outcome
ak.self.keys.keypackages.read.claim.v1POST /_arkret/self/keys/keypackages/claims/query--request_schema_ref=schemas/keypackage-operations.schema.json#/$defs/keypackages_claim_query_request_body; response_schema_ref=schemas/keypackage-operations.schema.json#/$defs/keypackages_claim_outcome
ak.self.keys.keypackages.upload.create.v1POST /_arkret/self/keys/keypackages/upload--request_schema_ref=schemas/keypackage-operations.schema.json#/$defs/keypackages_upload_request_body; response_schema_ref=schemas/keypackage-operations.schema.json#/$defs/keypackages_upload_outcome
ak.self.keys.read.lookup.v1POST /_arkret/self/keys/query--request_schema_ref=schemas/keys-operations.schema.json#/$defs/keys_query_request_body; response_schema_ref=schemas/keys-operations.schema.json#/$defs/keys_query_outcome
ak.self.keys.upload.create.v1POST /_arkret/self/keys/upload--request_schema_ref=schemas/keys-operations.schema.json#/$defs/keys_upload_request_body; response_schema_ref=schemas/keys-operations.schema.json#/$defs/keys_upload_outcome
ak.self.management_review.command.decide.v1POST /_arkret/self/management-reviews/decisions--request_schema_ref=schemas/management-review-operations.schema.json#/$defs/decision; response_schema_ref=schemas/management-review-operations.schema.json#/$defs/outcome
ak.self.management_review.command.request.v1POST /_arkret/self/management-reviews/requests--request_schema_ref=schemas/management-review-operations.schema.json#/$defs/request; response_schema_ref=schemas/management-review-operations.schema.json#/$defs/outcome
ak.self.management_review.read.status.v1POST /_arkret/self/management-reviews/status--request_schema_ref=schemas/management-review-operations.schema.json#/$defs/lookup; response_schema_ref=schemas/management-review-operations.schema.json#/$defs/outcome
ak.self.media.read.ice_config.v1POST /_arkret/self/rtc/ice-config--request_schema_ref=schemas/media-operations.schema.json#/$defs/media_ice_config_request_body; response_schema_ref=schemas/ice-config-response.schema.json
ak.self.media_service_binding.read.resolve.v1POST /_arkret/self/media-service-bindings/query--request_schema_ref=schemas/media-service-binding-result.schema.json#/$defs/media_service_binding_request_body; response_schema_ref=schemas/media-service-binding-result.schema.json#/$defs/media_service_binding_outcome
ak.self.messages.command.prepare.v1POST /_arkret/self/messages/prepare--request_schema_ref=schemas/message-authoring.schema.json#/$defs/message_prepare_request_body; response_schema_ref=schemas/message-authoring.schema.json#/$defs/message_prepare_outcome
ak.self.mls.read.group_state_material.v1POST /_arkret/self/mls/group-state-material/query--request_schema_ref=schemas/mls-roster-authority.schema.json#/$defs/member_group_state_material_read_request; response_schema_ref=schemas/service-operation-dtos.schema.json#/$defs/MlsGroupStateMaterialOutcome
ak.self.mls.read.roster_authority.v1POST /_arkret/self/mls/roster-authority/query--request_schema_ref=schemas/mls-roster-authority.schema.json#/$defs/member_roster_read_request; response_schema_ref=schemas/mls-roster-authority.schema.json#/$defs/self_roster_read_outcome
ak.self.moderation.command.report.v1POST /_arkret/self/moderation/report--request_schema_ref=schemas/moderation-report.schema.json#/$defs/moderation_report_request_body; response_schema_ref=schemas/service-operation-dtos.schema.json#/$defs/ModerationReportOutcome
ak.self.morph.read.list.v1GET /_arkret/self/realms/{realm_id}/morphs--response_schema_ref=schemas/service-operation-dtos.schema.json#/$defs/ProjectionMorphList
ak.self.morph.resource.get.v1GET /_arkret/self/realms/{realm_id}/morphs/{morph_id}--response_schema_ref=schemas/view.schema.json#/$defs/document_morph_projection_outcome
ak.self.read_cursor.command.advance.v1POST /_arkret/self/read-cursors--request_schema_ref=schemas/read-cursor-operations.schema.json#/$defs/read_cursor_advance_request_body; response_schema_ref=schemas/read-cursor-operations.schema.json#/$defs/read_marker_outcome
ak.self.read_cursor.read.list.v1GET /_arkret/self/read-cursors--response_schema_ref=schemas/read-cursor-operations.schema.json#/$defs/read_cursor_list
ak.self.realm.read.export.v1GET /_arkret/self/realms/{realm_id}/export--response_schema_ref=schemas/realm-read-operations.schema.json#/$defs/realm_export
ak.self.realm.read.streams.v1GET /_arkret/self/realms/{realm_id}/streams--response_schema_ref=schemas/realm-read-operations.schema.json#/$defs/realm_stream_list
ak.self.realm.resource.get.v1GET /_arkret/self/realms/{realm_id}--response_schema_ref=schemas/realm-read-operations.schema.json#/$defs/realm_lifecycle_view
ak.self.realm_join.command.prepare.v1POST /_arkret/self/realm-joins/prepare--request_schema_ref=schemas/realm-join-intake.schema.json#/$defs/self_prepare_request_body; response_schema_ref=schemas/realm-join-intake.schema.json#/$defs/self_prepare_outcome
ak.self.realm_join.read.preview.v1POST /_arkret/self/realm-joins/preview--request_schema_ref=schemas/realm-join-intake.schema.json#/$defs/self_preview_request_body; response_schema_ref=schemas/realm-join-intake.schema.json#/$defs/self_preview_outcome
ak.self.realm_link.read.list.v1GET /_arkret/self/realms/{realm_id}/links--response_schema_ref=schemas/realm-link-operations.schema.json#/$defs/realm_link_list
ak.self.realm_organization.read.list.v1GET /_arkret/self/realms/{realm_id}/organizations--response_schema_ref=schemas/realm-organization-operations.schema.json#/$defs/realm_organization_relationship_list
ak.self.realm_state_snapshot.read.by_ref.v1GET /_arkret/self/realm-state-snapshot/{snapshot_id}--response_schema_ref=schemas/realm-state-snapshot.schema.json
ak.self.realm_state_snapshot.read.manifest_head.v1GET /_arkret/self/realm-state-snapshot/head--response_schema_ref=schemas/realm-state-snapshot.schema.json
ak.self.security_transaction.command.continue.v1POST /_arkret/self/security-transactions/{transaction_id}/continue--request_schema_ref=schemas/security-transaction.schema.json#/$defs/continue_request; response_schema_ref=schemas/security-transaction.schema.json
ak.self.security_transaction.command.create.v1POST /_arkret/self/security-transactions--request_schema_ref=schemas/security-transaction.schema.json#/$defs/create_request; response_schema_ref=schemas/security-transaction.schema.json
ak.self.security_transaction.resource.get.v1GET /_arkret/self/security-transactions/{transaction_id}--response_schema_ref=schemas/security-transaction.schema.json
ak.self.signal.command.send.v1POST /_arkret/self/signal--request_schema_ref=schemas/signal-envelope.schema.json; response_schema_ref=schemas/service-operation-dtos.schema.json#/$defs/SignalSubmitOutcome
ak.self.signal.stream.subscribe.v1GET /_arkret/self/signal/subscribe--response_schema_ref=schemas/signal-stream-frame.schema.json
ak.self.signer_keys.read.resolve.v1POST /_arkret/self/signer-keys/query--request_schema_ref=schemas/signer-key-operations.schema.json#/$defs/query_request_body; response_schema_ref=schemas/signer-key-operations.schema.json#/$defs/query_outcome
ak.self.space.read.list.v1GET /_arkret/self/realms/{realm_id}/spaces--response_schema_ref=schemas/service-operation-dtos.schema.json#/$defs/ProjectionSpaceList
ak.self.strand.read.list.v1GET /_arkret/self/realms/{realm_id}/strands--response_schema_ref=schemas/service-operation-dtos.schema.json#/$defs/ProjectionStrandList
ak.self.strand.watch.read.current.v1POST /_arkret/self/strands/watch/current--request_schema_ref=schemas/service-operation-dtos.schema.json#/$defs/StrandWatchCurrentRequestBody; response_schema_ref=schemas/service-operation-dtos.schema.json#/$defs/StrandWatchCurrentOutcome
ak.self.third_party_invite.read.acceptance_attestation.v1POST /_arkret/self/third-party-invites/acceptance-attestation--request_schema_ref=schemas/invite.schema.json#/$defs/third_party_invite_acceptance_attestation_request_body; response_schema_ref=schemas/invite.schema.json#/$defs/third_party_invite_acceptance_attestation_outcome
ak.server.read.describe.v1GET /_arkret/describe--response_schema_ref=schemas/service-describe.schema.json