{
  "$schema": "https://json-schema.org/draft/2020-12/schema",
  "$id": "https://qlaas.co.uk/spec/dmi-receipt-0.1.schema.json",
  "title": "Qlaas DMI signed receipt (format 0.1)",
  "description": "One signed, hash-chained decision record. signature = Ed25519 over JCS(payload); payload.prev = base64url(SHA-256(JCS(previous signed receipt))). Individual draft; not an adopted standard.",
  "type": "object",
  "required": [
    "payload",
    "signature",
    "keyId"
  ],
  "properties": {
    "payload": {
      "type": "object",
      "required": [
        "v",
        "id",
        "at",
        "prev",
        "actor",
        "action",
        "decision",
        "reasons"
      ],
      "properties": {
        "v": {
          "enum": [
            "qlaas.receipt/0.1",
            "playbakk.receipt/0.1"
          ]
        },
        "id": {
          "type": "string",
          "pattern": "^rcpt_[A-Za-z0-9_-]{1,64}$"
        },
        "at": {
          "type": "string",
          "format": "date-time"
        },
        "prev": {
          "type": [
            "string",
            "null"
          ],
          "pattern": "^[A-Za-z0-9_-]{43}$"
        },
        "actor": {
          "type": "object",
          "required": [
            "kind",
            "id"
          ],
          "properties": {
            "kind": {
              "enum": [
                "agent",
                "owner",
                "system"
              ]
            },
            "id": {
              "type": "string",
              "minLength": 1
            }
          }
        },
        "counterparty": {
          "type": "object",
          "required": [
            "id",
            "kind",
            "tier"
          ],
          "properties": {
            "id": {
              "type": "string",
              "minLength": 1
            },
            "kind": {
              "enum": [
                "human",
                "agent",
                "business"
              ]
            },
            "tier": {
              "enum": [
                "observed",
                "declared",
                "verified",
                "inferred",
                "verified-intermediary"
              ]
            }
          }
        },
        "action": {
          "type": "string",
          "pattern": "^[a-z][a-z0-9_-]*(\\.[a-z][a-z0-9_-]*)+$"
        },
        "decision": {
          "enum": [
            "ALLOW",
            "STEP_UP",
            "DENY"
          ]
        },
        "subject": {
          "type": "object"
        },
        "reasons": {
          "type": "array",
          "items": {
            "type": "string"
          }
        }
      }
    },
    "signature": {
      "type": "string",
      "pattern": "^[A-Za-z0-9_-]{86}$"
    },
    "keyId": {
      "type": "string",
      "minLength": 1
    }
  }
}
