File size: 3,029 Bytes
1d3f990
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
{
  "$schema": "http://json-schema.org/draft-07/schema#",
  "title": "Capability Schema",
  "description": "Cryptographic capability object for authorization",
  "type": "object",
  "required": [
    "capability_version",
    "capability_id",
    "issuer_id",
    "agent_id",
    "target_runtime",
    "permissions",
    "issued_at",
    "expires_at",
    "signature"
  ],
  "properties": {
    "capability_version": {
      "type": "string",
      "description": "Schema version",
      "enum": ["1.0"]
    },
    "capability_id": {
      "type": "string",
      "description": "Unique capability identifier",
      "minLength": 32,
      "maxLength": 64
    },
    "issuer_id": {
      "type": "string",
      "description": "Agent ID that issued this capability (typically cipher)",
      "minLength": 1,
      "maxLength": 50
    },
    "agent_id": {
      "type": "string",
      "description": "Agent that holds this capability",
      "minLength": 1,
      "maxLength": 50
    },
    "target_runtime": {
      "type": "string",
      "enum": ["rust", "ada", "holyc", "haskell", "emoji", "python3"],
      "description": "Runtime this capability applies to"
    },
    "permissions": {
      "type": "array",
      "description": "List of permissions granted",
      "items": {
        "type": "string",
        "minLength": 1,
        "maxLength": 50
      },
      "minItems": 1
    },
    "resource_limits": {
      "type": "object",
      "description": "Resource constraints",
      "properties": {
        "max_memory_bytes": {
          "type": "integer",
          "minimum": 0
        },
        "max_cpu_seconds": {
          "type": "integer",
          "minimum": 0
        },
        "max_dispatch_count": {
          "type": "integer",
          "minimum": 0
        }
      }
    },
    "issued_at": {
      "type": "integer",
      "description": "Unix timestamp when capability was issued",
      "minimum": 0
    },
    "expires_at": {
      "type": "integer",
      "description": "Unix timestamp when capability expires",
      "minimum": 0
    },
    "nonce": {
      "type": "string",
      "description": "Random nonce for uniqueness",
      "minLength": 16,
      "maxLength": 64
    },
    "parent_capability_hash": {
      "type": ["string", "null"],
      "description": "Hash of parent capability (for delegation chains)",
      "pattern": "^([a-f0-9]{64}|null)$"
    },
    "revocation_reference": {
      "type": ["string", "null"],
      "description": "Hash of revocation record if capability has been revoked"
    },
    "signature": {
      "type": "string",
      "description": "Ed25519 signature of capability object",
      "minLength": 128,
      "maxLength": 128,
      "pattern": "^[a-f0-9]{128}$"
    },
    "metadata": {
      "type": "object",
      "description": "Optional metadata",
      "additionalProperties": true
    }
  },
  "additionalProperties": false
}