{"lexicon":1,"id":"money.atmosphere.payment.verifyReceipt","defs":{"main":{"type":"query","description":"EXPERIMENTAL DRAFT — unpublished exact-evidence verification of one receipt generation. Every fragment identifier below is local to this NSID: for example, #attested means money.atmosphere.payment.verifyReceipt#attested and is not imported from network.attested.*. Request parameters do not grant trust or source qualification. The response carries complete authenticated same-head lifecycle segment observations and signed-commit/MST evidence; bounded direct reads report only a prefix. Current published status requires a named independently qualified gap-free source or complete exhaustion evidence at one signed head, never promotion of a prefix. Record/proof/lifecycle/retraction acquisition and cryptographic provenance are the separately qualified adapter's responsibility; the pure algorithm consumes that trusted evidence and does not itself authenticate a repository signature or exclusion proof. Retraction checks bind the exact receipt author, location and generation. Unknown union branches grant no effects. Legacy-family verifyRecord has a separate unchanged contract. COMMITMENT_PROFILE.md defines the exact semantics and fail-closed boundaries.","parameters":{"type":"params","required":["uri","cid"],"properties":{"uri":{"type":"string","format":"at-uri","description":"AT-URI of the exact receipt record to verify. Semantic request validation requires collection money.atmosphere.payment.receipt or money.atmosphere.payment.recurringReceipt plus a nonempty record key; collection-only or wrong-collection URIs are rejected before fetch because generic format: at-uri cannot enforce this exact-record boundary."},"cid":{"type":"string","format":"cid","description":"Canonical AT repository-record CID of the exact generation being verified: lowercase unpadded base32 CIDv1, dag-cbor codec, sha2-256 with a 32-byte digest. Semantic request validation enforces that profile before any fetch. Verification is always against one exact generation, never \"whatever is there now\"."},"attester":{"type":"string","format":"did","description":"Optional single-attester FILTER intersected with the service's fixed trust policy. A proof from an attester outside that trust set NEVER yields attestation. Supplying `attester` can only narrow results, never widen trust. A service needing a multi-attester filter MUST define a separately reviewed request shape; a neutral verify-any-attester surface would be separate and explicitly non-authoritative."}}},"output":{"encoding":"application/json","schema":{"type":"object","required":["result","policyEvaluation"],"properties":{"result":{"type":"union","refs":["#current","#cidMismatch","#absent","#unavailable","#retracted","#retractionInvalid"],"description":"Exactly one settlement-evidence variant. Open union; consumers MUST fail closed on unknown variants for authorization purposes. Neither #current receipt presence nor #attested settlement is evaluation of the separately requested role policy; consult the mandatory policyEvaluation boundary."},"policyEvaluation":{"type":"ref","ref":"#policyEvaluation","description":"Mandatory machine-readable boundary of the intermediate settlement-only algorithm. Requested policy identity is echoed, not evaluated. It cannot grant trust-policy success, standing, current access or authorization. Contract C role, history and account-state evaluation remains separately gated."}}}}},"policyEvaluation":{"type":"object","description":"The settlement-only core has not evaluated this requested role policy. Every successful algorithm response carries status not-evaluated and authorization none, including malformed, absent, retracted and otherwise attested settlement observations. Input validation errors are not protocol output records. Unknown versions, scopes, IDs or status must fail closed; no fallback policy is implied.","required":["id","version","scope","status","authorization"],"properties":{"id":{"type":"string","maxLength":64,"knownValues":["broker-trusted","creator-trusted","strict-identified","strict-independent-identified","guest-broker-trusted","guest-corroborated"]},"version":{"type":"integer","minimum":1,"maximum":1},"scope":{"type":"string","maxLength":10,"knownValues":["historical","standing"]},"status":{"type":"string","maxLength":16,"knownValues":["not-evaluated"]},"authorization":{"type":"string","maxLength":4,"knownValues":["none"]}}},"current":{"type":"object","description":"The requested exact receipt generation is present at the authenticated observation boundary and its co-located retraction observation does not contain a valid retraction. Absence of a retraction at this head is not proof none was ever authored. This outer record-presence variant does not assert that its nested lifecycle result is current; consult the nested prefix/current classification.","required":["block","author","settlement","evidenceAsOf"],"properties":{"block":{"type":"ref","ref":"#blockEvidence","description":"Exact authenticated repository block evidence for this generation."},"record":{"type":"unknown","description":"The exact decoded receipt record. Required by the normative profile for every settlement variant except #recordInvalid, and omitted for #recordInvalid so malformed data can never be laundered through the JSON response codec. Consumers validate it against block.bytes before use."},"author":{"type":"string","format":"did","description":"Author DID derived from authenticated provenance; the DID used in the commitment recomputation."},"settlement":{"type":"union","refs":["#attested","#recordInvalid","#unattested","#invalidEvidence","#unsupportedProfile","#proofReplaced","#proofAbsent","#settlementUnavailable"],"description":"Settlement-evidence bundle (with lifecycle nested under #attested). Semantic receipt validation runs first (#recordInvalid — includes a stored $commit key; a legacy, unknown, mixed, or non-canonical value form; non-canonical nonce/settledAt forms; and non-DID or wrong-collection proof references; the full list is normative in COMMITMENT_PROFILE.md); then every trusted proof reference is classified independently; outcome precedence (#attested > #settlementUnavailable > #unsupportedProfile > #invalidEvidence > not-current (#proofReplaced/#proofAbsent, one combined selection bucket — the variant is derived from the selected entry) > #unattested) and deterministic selection are normative in COMMITMENT_PROFILE.md. No DECLARED settlement variant carries lifecycle evidence except #attested; because Lexicon unions are open and unexpected properties are ignored, consumers MUST fail closed on unknown union variants and MUST NOT read undeclared or extra properties as evidence. The receipt's committed settlement union admits only #processorSettlement here and requires at least one proof; the schema's zero bound reserves later profiles without activating them."},"evidenceAsOf":{"type":"string","format":"datetime","description":"The evidence boundary used to produce this response."}}},"attested":{"type":"object","description":"Immutable evidence from a trusted attester inside the service's trust set supports the historical settlement assertion for exactly this record generation. Unaffected by later refunds/disputes (see lifecycle).","required":["proof","proofRecord","attester","lifecycle","lifecyclePaths"],"properties":{"proof":{"type":"ref","ref":"com.atproto.repo.strongRef","description":"Exact reference (uri + record CID) to the immutable proof record."},"proofRecord":{"type":"unknown","description":"The verifying proof record, verbatim. The service MUST have validated it (lexicon-valid proof, verified commitment) before returning this variant — the type is unknown only because Lexicon record definitions cannot be embedded in XRPC outputs."},"attester":{"type":"string","format":"did","description":"Authenticated controlling DID of the attesting repository."},"lifecycle":{"type":"union","refs":["#lifecycleKnown","#lifecycleMissing","#lifecycleInvalid","#lifecycleUnavailable","#noLifecycleAuthority"],"description":"Lifecycle-evidence bundle. Scope: EVERY logical receipt proof reference whose attester is a trusted lifecycle authority is a lifecycle CANDIDATE PATH — including candidates whose own proof could not be verified (unreachable, replaced, absent, unsupported, invalid): an unresolved candidate BLOCKS a clean settled outcome, so a candidate-resolution outage cannot be mistaken for a clean observation (normative in COMMITMENT_PROFILE.md). This does NOT turn the public lifecycle chain into synchronous ledger truth: lifecycle records are eventual projections, and even a validated `settled` observation MUST NOT be used as the sole real-time payment or entitlement authorization; callers requiring current truth use the deploying consumer's canonical authoritative settlement ledger/API. Paths are identified by (attesterDid, exact proofUri string, decoded proofCid bytes). Selection is by fail-closed CATEGORY order (validated non-settled > missing > invalid > unavailable > validated settled), with bytewise attester DID, proof URI, then decoded CID bytes breaking ties inside the winning category; revisions are PER-PATH and never compared across authorities. Nested here because lifecycle state is defined only relative to trusted attestation: no DECLARED variant pairs lifecycle evidence with a non-attested outcome. Open union; unknown variants fail closed."},"lifecyclePaths":{"type":"array","maxLength":10,"items":{"type":"union","refs":["#pathValidated","#pathMissing","#pathInvalid","#pathUnresolved"],"description":"Typed per-outcome observation. Open union; consumers MUST fail closed on unknown variants."},"description":"EXHAUSTIVE typed enumeration of EVERY logical lifecycle candidate path — the same set the aggregation evaluated (bounded by the receipt's proofs maxLength, which is also 10). NORMATIVE CLOSURE (COMMITMENT_PROFILE.md): exactly one observation per candidate path (exact candidate-set equality — no omissions, no extras); unique (attesterDid, exact proofUri string, decoded proofCid bytes) identities; ordered ascending by bytewise attester DID, proof URI, then decoded CID bytes; each observation the union variant matching the path's classification, carrying that variant's REQUIRED evidence. The representative `lifecycle` variant MUST equal the category-then-path selection recomputed from this array, its evidence fields MUST be the SAME observation as the selected entry's (the per-variant-pair SHARED-field projection defined in COMMITMENT_PROFILE.md — never an independent re-read), and this array is empty IFF `lifecycle` is #noLifecycleAuthority. Consumers MUST recompute the aggregation and fail closed on ANY inconsistency — duplicate/missing/extra paths, unknown observation variants, or a mismatched representative. For a later segment, response-local recomputation independently checks only the final window and supplied priorPrefix terminal block/link; earlier-window coverage rests on the qualified acquisition adapter's authenticated same-head prior coverage. This response is adapter-attested for that earlier coverage, not self-contained full-chain verification; fully independent verification requires obtaining and authenticating every earlier window. The current local stateless corpus exercises this emission-side closure, while consumption belongs to the separate stateful-consumer role. Conformance status is tracked only in COMMITMENT_PROFILE.md."}}},"unattested":{"type":"object","description":"No proof from a trusted attester was found for this generation. Not evidence of anything beyond absence-of-proof at the evidence boundary.","properties":{}},"invalidEvidence":{"type":"object","description":"Proof material from a trusted attester exists and was fetched, but failed verification: commitment recomputation mismatch or a malformed proof record. Exact authenticated block evidence is returned so the claim is inspectable even when malformed bytes cannot cross Lex-JSON as a decoded value. Fails closed — never collapsed into unattested. Precedence and deterministic selection are normative in COMMITMENT_PROFILE.md.","required":["proof","block","reason"],"properties":{"proof":{"type":"ref","ref":"com.atproto.repo.strongRef","description":"Exact reference to the proof record that failed verification (deterministically selected when several fail; see COMMITMENT_PROFILE.md)."},"block":{"type":"ref","ref":"#blockEvidence","description":"Exact authenticated proof block evidence."},"reason":{"type":"string","maxLength":64,"knownValues":["commitment-mismatch","proof-malformed"],"description":"Machine-readable failure class (kebab-case)."}}},"settlementUnavailable":{"type":"object","description":"The attesting repository or index could not be reached or authenticated; no settlement claim is made. NOT evidence of absence.","required":["attester","retryable"],"properties":{"attester":{"type":"string","format":"did","description":"The unreachable attesting repository’s DID (deterministically selected when several are unreachable)."},"retryable":{"type":"boolean","description":"OR of the transient classifications across ALL unreachable trusted attesters: true when at least one failure looked transient."}}},"lifecycleKnown":{"type":"object","description":"Aggregated lifecycle evidence from the selected path, carrying its exact terminal record and complete authenticated window. Category-then-path precedence remains fail closed; revisions never order different authorities' paths. The record, proof, URI, CID, block and classification must match the selected lifecyclePaths entry. prefix is a lower bound; only separately verified qualified-source evidence permits current. Immutable revision strongRefs are stable historical identities.","required":["proof","uri","cid","block","record","classification","window"],"properties":{"uri":{"type":"string","format":"at-uri"},"cid":{"type":"string","format":"cid","description":"Record CID of the exact lifecycle generation this response reports."},"record":{"type":"unknown","description":"The lifecycle record at the returned exact cid, verbatim. The service MUST have validated it (lexicon-valid, its proof strongRef equal to THIS LIFECYCLE PATH's proof) before returning this variant; consumers read status and revision from it."},"block":{"type":"ref","ref":"#blockEvidence","description":"Exact authenticated lifecycle block evidence. Consumers require its canonical decode to equal record and its CID to equal cid."},"proof":{"type":"ref","ref":"com.atproto.repo.strongRef","description":"The lifecycle path's own verifying proof (its exact strongRef) — the path this evidence is bound to. May differ from the outer #attested.proof: settlement selection and lifecycle selection are independent."},"classification":{"type":"union","refs":["#lifecyclePrefix","#lifecycleCurrent"],"description":"Separate prefix/current classification; a validated record alone does not establish currentness."},"window":{"type":"ref","ref":"#lifecycleWindow"}}},"lifecycleUnavailable":{"type":"object","description":"A lifecycle-authority candidate path could not be resolved to a definitive state. An unverified lifecycle authority may hold a restrictive state, so while any candidate is unresolved a clean settled result is impossible. The representative path is selected deterministically and its cause is returned as a typed evidence-bearing variant; aggregate retryability is reported separately because the representative's own failure class may be permanent while another unresolved path's is transient.","required":["proof","cause","retryable"],"properties":{"proof":{"type":"ref","ref":"com.atproto.repo.strongRef","description":"The representative unresolved candidate path (deterministically selected by lowest bytewise path triple among ALL unresolved candidates)."},"cause":{"type":"union","refs":["#causeSidecarUnreachable","#causeProofUnreachable","#causeProofReplaced","#causeProofAbsent","#causeProofUnsupportedProfile","#causeProofInvalid"],"description":"Why the representative path is unresolved — each cause variant schema-REQUIRES its own evidence. Open union; unknown variants fail closed."},"retryable":{"type":"boolean","description":"Aggregate retryability. MUST equal the OR of the DERIVED per-path classifications across all unresolved candidate paths (a path is transient IFF its observation's cause is an unreachable variant with transient: true; replaced/absent/unsupported/invalid causes are permanent), and the representative `cause` on this variant MUST be THE SAME observation as the selected path's lifecyclePaths entry — identical declared-field values, compared as decoded Lex values over declared fields only (transport bytes are not canonical; consumers may equivalently read the cause from the selected array entry). Lexicon cannot express these cross-field rules; the current local stateless corpus supplies executable emission-side evidence. Conformance status is tracked only in COMMITMENT_PROFILE.md."}}},"cidMismatch":{"type":"object","description":"A record exists at the uri in the current repository, but its current generation's canonical payment-v1 record CID differs from the requested canonical payment-v1 record CID. Both values have already passed the required lowercase-unpadded-base32 CIDv1 / dag-cbor / sha2-256/32 preflight, so there is exactly one permitted text for each CID byte sequence. No claim is made about the requested cid's history: a requested cid may be a prior generation or may never have been published at this uri — distinguishing those requires authenticated commit-history evidence this response does not carry.","required":["currentCid","evidenceAsOf"],"properties":{"currentCid":{"type":"string","format":"cid","description":"The record CID currently at the uri, from an authenticated current-head read."},"evidenceAsOf":{"type":"string","format":"datetime"}}},"absent":{"type":"object","description":"The current repository authoritatively contains no record at the uri. Distinct from unavailability, and NOT itself evidence of retraction or deletion intent — only of current absence. Historical proof evidence may still verify for parties holding old bytes.","required":["confirmedAt"],"properties":{"confirmedAt":{"type":"string","format":"datetime","description":"When current-repository absence was authoritatively confirmed."}}},"unavailable":{"type":"object","description":"The receipt's repository host or index could not be reached or authenticated. NOT evidence of absence; callers should retry. No claim of any kind is made.","required":["retryable"],"properties":{"retryable":{"type":"boolean"}}},"recordInvalid":{"type":"object","description":"The record at the exact requested CID is not a valid receipt: it fails authenticated AT-CBOR decoding, its lexicon, a normative semantic check (including a legacy/unknown/mixed value, non-canonical amountMinor/currency or amountAtomic/asset, nonce hex form, settledAt grammar, presence of a stored $commit key, or non-DID-authority/wrong-collection proof references), the 65536-byte payment-v1 record limit, or the COMMITTED DATA DOMAIN — null anywhere, non-integral or unsafe-range numbers, lone-surrogate strings, __proto__ or / map keys, container nesting beyond depth 32, CID/bytes values, or native/exotic host values. This parenthetical is a summary, NOT the definition: the complete normative list lives in COMMITMENT_PROFILE.md and governs. No settlement evaluation is possible; evaluated FIRST, before any proof. Exact evidence is already carried by #current.block, so this variant needs no further fields.","properties":{}},"unsupportedProfile":{"type":"object","description":"A trusted attester’s proof names a commitment profile this implementation does not implement — evidence exists that cannot be judged. Fails closed per proof; never masks a verifying supported proof (see precedence in COMMITMENT_PROFILE.md).","required":["proof","profile"],"properties":{"proof":{"type":"ref","ref":"com.atproto.repo.strongRef","description":"Exact reference to the unjudgeable proof (deterministically selected when several)."},"profile":{"type":"string","maxLength":64,"description":"The unrecognized profile token, verbatim."}}},"lifecycleInvalid":{"type":"object","description":"Aggregated sticky lifecycle integrity result backed by the exact selected path's offending record and complete signed-head window. Wrong proof, invalid record, predecessor mismatch or a visible hole cannot be interpreted as settled or downgraded to a clean prefix. The representative evidence must equal its selected lifecyclePaths entry.","required":["proof","uri","cid","block","reason","window"],"properties":{"uri":{"type":"string","format":"at-uri"},"cid":{"type":"string","format":"cid","description":"Record CID of the exact offending generation."},"block":{"type":"ref","ref":"#blockEvidence","description":"Exact authenticated lifecycle block evidence."},"reason":{"type":"string","maxLength":64,"knownValues":["record-invalid","wrong-proof-binding","chain-integrity"],"description":"Machine-readable failure class (kebab-case)."},"proof":{"type":"ref","ref":"com.atproto.repo.strongRef","description":"The candidate path (its proof strongRef) whose lifecycle chain is unusable."},"window":{"type":"ref","ref":"#lifecycleWindow"}}},"proofReplaced":{"type":"object","description":"An authenticated current-head read of the attesting repository shows a record at the referenced URI whose CID differs from the pinned reference. Current-state evidence ONLY: no claim is made about whether the pinned generation ever existed at that URI, and no intent is attributed. The pinned reference is therefore not standing evidence.","required":["proof","currentCid"],"properties":{"proof":{"type":"ref","ref":"com.atproto.repo.strongRef","description":"The receipt’s pinned reference (deterministically selected when several; see COMMITMENT_PROFILE.md)."},"currentCid":{"type":"string","format":"cid","description":"The record CID currently at the URI, from the authenticated current-head read."}}},"proofAbsent":{"type":"object","description":"An authenticated current-head read of the attesting repository shows NO record at the referenced URI. Current-state evidence ONLY: no claim is made about whether the pinned generation ever existed, and no intent is attributed. The pinned reference is therefore not standing evidence.","required":["proof","confirmedAt"],"properties":{"proof":{"type":"ref","ref":"com.atproto.repo.strongRef","description":"The receipt’s pinned reference (deterministically selected when several; see COMMITMENT_PROFILE.md)."},"confirmedAt":{"type":"string","format":"datetime","description":"When current absence was authoritatively confirmed."}}},"lifecycleMissing":{"type":"object","description":"Fail-closed aggregated missing-genesis alarm, backed by the same complete window/classification as its selected per-path observation. Empty bounded evidence does not prove the absence of every hidden suffix or restore authorization.","required":["proof","confirmedAt","classification","window"],"properties":{"confirmedAt":{"type":"string","format":"datetime","description":"When current absence was authoritatively confirmed."},"proof":{"type":"ref","ref":"com.atproto.repo.strongRef","description":"The candidate path (its proof strongRef) whose authenticated deterministic lifecycle window has no present revision."},"classification":{"type":"union","refs":["#lifecyclePrefix","#lifecycleCurrent"],"description":"Separate prefix/current classification; a validated record alone does not establish currentness."},"window":{"type":"ref","ref":"#lifecycleWindow"}}},"noLifecycleAuthority":{"type":"object","description":"The verifier's trust policy contains no lifecycle authority among this receipt's proof references — a PERMANENT policy limitation, distinct from evidence failure: nothing was unreadable; there is simply no authority to consult. Consumers requiring lifecycle assurance must extend their trust policy.","properties":{}},"causeSidecarUnreachable":{"type":"object","description":"The candidate's proof verified but its lifecycle window could not be read or authenticated.","required":["transient"],"properties":{"transient":{"type":"boolean","description":"This path's own failure classification per the profile's taxonomy."}}},"causeProofUnreachable":{"type":"object","description":"The candidate's own proof repository could not be reached or authenticated this pass.","required":["transient"],"properties":{"transient":{"type":"boolean","description":"This path's own failure classification per the profile's taxonomy."}}},"causeProofReplaced":{"type":"object","description":"An authenticated current-head read shows a different record CID at the candidate's proof URI. Permanent for retry purposes.","required":["currentCid"],"properties":{"currentCid":{"type":"string","format":"cid","description":"The record CID currently at the URI."}}},"causeProofAbsent":{"type":"object","description":"An authenticated current-head read shows no record at the candidate's proof URI. Permanent for retry purposes.","required":["confirmedAt"],"properties":{"confirmedAt":{"type":"string","format":"datetime","description":"When current absence was authoritatively confirmed."}}},"causeProofUnsupportedProfile":{"type":"object","description":"The candidate's proof names a commitment profile this implementation does not implement. Permanent for retry purposes (an upgrade, not a retry, resolves it).","required":["profile"],"properties":{"profile":{"type":"string","maxLength":64,"description":"The unrecognized profile token, verbatim."}}},"causeProofInvalid":{"type":"object","description":"The candidate's proof was fetched but failed verification. Permanent for retry purposes. Exact authenticated block evidence is carried even when malformed content cannot be represented as Lex-JSON.","required":["reason","block"],"properties":{"reason":{"type":"string","maxLength":64,"knownValues":["commitment-mismatch","proof-malformed"],"description":"Machine-readable failure class (kebab-case)."},"block":{"type":"ref","ref":"#blockEvidence","description":"Exact authenticated proof block evidence."}}},"pathValidated":{"type":"object","description":"Validated contiguous immutable lifecycle prefix for this proof path, bound to the exact terminal record/block/CID and deterministic segmented URI. status and revision equal the record; proof remains identical across every predecessor; classification.throughRevision equals the contiguous tip. Every observation and any continuation must verify at one signed head. For a later segment, a response-local consumer independently recomputes only the final window and the supplied priorPrefix terminal block/link; earlier coverage is adapter-attested through the qualified acquisition adapter's authenticated same-head prior coverage. The response does not carry every earlier window, so it is not self-contained full-chain verification. Validation is not automatically currentness or authorization.","required":["proof","status","revision","uri","cid","block","record","classification","window"],"properties":{"proof":{"type":"ref","ref":"com.atproto.repo.strongRef","description":"The path (its proof strongRef)."},"uri":{"type":"string","format":"at-uri"},"cid":{"type":"string","format":"cid","description":"Exact record CID observed at this path — the high-water candidate generation. MUST be recomputable as the repository-record CID of the exact verbatim record."},"status":{"type":"string","maxLength":64,"knownValues":["settled","refunded","partially-refunded","disputed","reversed"],"description":"The record's status (kebab-case; open set — unknown values fail closed for authorization). MUST equal the verbatim record's own status field."},"revision":{"type":"integer","minimum":1,"maximum":9007199254740991,"description":"The record's per-path revision. MUST equal the verbatim record's own revision field."},"record":{"type":"unknown","description":"The lifecycle record at the returned cid, verbatim."},"block":{"type":"ref","ref":"#blockEvidence","description":"Exact authenticated lifecycle block evidence. Consumers require its canonical decode to equal record and its CID to equal cid."},"classification":{"type":"union","refs":["#lifecyclePrefix","#lifecycleCurrent"],"description":"Separate prefix/current classification; a validated record alone does not establish currentness."},"window":{"type":"ref","ref":"#lifecycleWindow"}}},"pathMissing":{"type":"object","description":"Authenticated absence of lifecycle genesis, with the complete window and classification retained. Genesis is required for a lifecycle-authority proof, so this is an integrity alarm, never good standing. A stateful consumer retains sticky evidence and does not auto-clear it on reappearance.","required":["proof","confirmedAt","classification","window"],"properties":{"proof":{"type":"ref","ref":"com.atproto.repo.strongRef","description":"The path (its proof strongRef)."},"confirmedAt":{"type":"string","format":"datetime","description":"When current absence was authoritatively confirmed."},"classification":{"type":"union","refs":["#lifecyclePrefix","#lifecycleCurrent"],"description":"Separate prefix/current classification; a validated record alone does not establish currentness."},"window":{"type":"ref","ref":"#lifecycleWindow"}}},"pathInvalid":{"type":"object","description":"Sticky per-path integrity evidence: malformed/wrong-bound lifecycle record, non-dense revision or predecessor, interior deletion/hole, or an occupied deterministic key with different bytes. The offending present block and the complete signed-head window are retained; the representative URI/CID/block must identify that exact observed record. No automatic repair or later clean record clears the evidence.","required":["proof","uri","cid","block","reason","window"],"properties":{"proof":{"type":"ref","ref":"com.atproto.repo.strongRef","description":"The path (its proof strongRef)."},"uri":{"type":"string","format":"at-uri"},"cid":{"type":"string","format":"cid","description":"Record CID of the exact offending generation."},"block":{"type":"ref","ref":"#blockEvidence","description":"Exact authenticated lifecycle block evidence."},"reason":{"type":"string","maxLength":64,"knownValues":["record-invalid","wrong-proof-binding","chain-integrity"],"description":"Machine-readable failure class (kebab-case)."},"window":{"type":"ref","ref":"#lifecycleWindow"}}},"blockEvidence":{"type":"object","description":"Authenticated repository block evidence. encodedBytes is always the exact block length. bytes is REQUIRED by the normative profile when encodedBytes is at most 65536 and MUST equal the complete authenticated block; bytes is OMITTED when encodedBytes is larger, so an oversized hostile record cannot force an unbounded verification response. The record CID or proof strongRef carried by the parent authenticates either form.","required":["encodedBytes"],"properties":{"encodedBytes":{"type":"integer","minimum":0,"maximum":9007199254740991},"bytes":{"type":"bytes","maxLength":65536}}},"pathUnresolved":{"type":"object","description":"Per-path observation: this candidate could not be resolved to a definitive state (its own proof did not verify this pass, or its lifecycle window was unreachable). The typed cause carries its own required evidence and is the SINGLE source of this path's retry classification: a path is transient IFF its cause is an unreachable variant with transient: true; replaced/absent/unsupported/invalid causes are permanent. Stateful rule (COMMITMENT_PROFILE.md): after a path validated, proof-replaced/proof-absent/proof-invalid permanently sets its sticky integrity-compromised state; unreachable causes park/retry without themselves compromising history; unsupported-profile remains fail-closed policy limitation; no later exact record automatically clears retained bad evidence. There is deliberately no separate per-path transient field — duplicating the classification invited schema-valid contradictions.","required":["proof","cause"],"properties":{"proof":{"type":"ref","ref":"com.atproto.repo.strongRef","description":"The path (its proof strongRef)."},"cause":{"type":"union","refs":["#causeSidecarUnreachable","#causeProofUnreachable","#causeProofReplaced","#causeProofAbsent","#causeProofUnsupportedProfile","#causeProofInvalid"],"description":"Why this path is unresolved — each cause variant schema-REQUIRES its own evidence. Open union; unknown variants fail closed."}}},"settlementOutcome":{"type":"string","knownValues":["chain-verified","settlement-unavailable"],"maxLength":64,"description":"Reserved vocabulary only for separately reviewed future settlement profiles. This cut emits no chain-verified outcome and implements no chain or Zone verification. settlement-unavailable names inaccessible future settlement evidence and never means invalid. Existing processor evidence uses its declared response variants."},"repositoryEvidence":{"type":"object","required":["signedCommit","mstBlocks"],"description":"Complete signed commit block and deduplicated MST blocks for every present or absent window key, the candidate proof and any prior terminal at one head. The verifier independently binds the canonical commit CID, DID and data root and verifies each required inclusion/exclusion path. The acquisition adapter separately authenticates the signature and DID key, current-source qualification and earlier-window history; these are not proved by local Merkle consistency. Nonempty bytes alone authenticate nothing. The profile bounds signed-commit plus MST bytes to 2 MiB and separately bounds repository decoding and traversal. An adapter unable to provide complete evidence reports unavailable; malformed or incomplete supplied evidence is invalid, never an abbreviated prefix claim.","properties":{"signedCommit":{"type":"bytes","maxLength":65536,"description":"Exact authenticated signed repository commit block for repositoryState."},"mstBlocks":{"type":"array","maxLength":128,"items":{"type":"bytes","maxLength":65536},"description":"Shared MST proof blocks, each included once; every requested path is provable from this set and the signed commit. The profile enforces nonempty valid blocks, deduplication and the aggregate 2 MiB limit across the signed commit and all MST blocks."}}},"lifecyclePresent":{"type":"object","required":["revision","uri","cid","block","repositoryState"],"description":"One complete present-key observation in the segment window. Revision and URI are the deterministic requested key, not a claim extracted from unvalidated record fields; cid hashes block and the repository proof binds this exact URI at the window head.","properties":{"revision":{"type":"integer","minimum":1,"maximum":9007199254740991},"uri":{"type":"string","format":"at-uri"},"cid":{"type":"string","format":"cid"},"block":{"type":"ref","ref":"#blockEvidence"},"repositoryState":{"type":"string","minLength":1,"maxLength":2048,"description":"Canonical DAG-CBOR/SHA-256 CID of the exact signed commit in repositoryEvidence. The verifier derives this identity from those bytes; all observations for this authority at this head must match. The existing 1..512 UTF-16-code-unit bound also applies. Opaque proof-only or unavailable observations retain their separate state-label domain; this segment label alone authenticates no signature or current-source claim."}}},"lifecycleAbsent":{"type":"object","required":["revision","uri","confirmedAt","repositoryState"],"description":"One authenticated excluded key in the segment window, proven against the same signed commit/MST as every other observation. A missing response or RecordNotFound without exclusion evidence is not this observation.","properties":{"revision":{"type":"integer","minimum":1,"maximum":9007199254740991},"uri":{"type":"string","format":"at-uri"},"confirmedAt":{"type":"string","format":"datetime"},"repositoryState":{"type":"string","minLength":1,"maxLength":2048,"description":"Opaque authenticated repository-state identity. Profile validation retains the existing 1..512 UTF-16-code-unit Unicode-scalar bound; all observations for one authority use exactly this same state. This label alone authenticates nothing."}}},"priorPrefix":{"type":"object","required":["proof","repositoryState","throughRevision","terminal","terminalBlock"],"description":"Continuation witness supplied only by the qualified acquisition adapter after it validates every prior segment at this same signed head. Required exactly when startRevision > 1: throughRevision equals startRevision-1, and terminal names that exact deterministic predecessor URI/CID. A response-local consumer can verify the supplied terminal block/link and final window, but earlier coverage rests on the adapter's authenticated prior coverage. This summary and a strongRef alone are insufficient independent proof of earlier coverage; a consumer requiring full-chain independent verification must obtain and authenticate every earlier window rather than treat this adapter-attested continuation as self-contained proof.","properties":{"proof":{"type":"ref","ref":"com.atproto.repo.strongRef"},"repositoryState":{"type":"string","minLength":1,"maxLength":2048,"description":"Opaque authenticated repository-state identity. Profile validation retains the existing 1..512 UTF-16-code-unit Unicode-scalar bound; all observations for one authority use exactly this same state. This label alone authenticates nothing."},"throughRevision":{"type":"integer","minimum":1,"maximum":9007199254740991},"terminal":{"type":"ref","ref":"com.atproto.repo.strongRef"},"terminalBlock":{"type":"ref","ref":"#blockEvidence","description":"Exact authenticated predecessor terminal record block. Its CID, proof binding and revision must equal terminal, proof and throughRevision; the complete prior-window authentication prerequisite still applies."}}},"lifecycleWindow":{"type":"object","required":["startRevision","repositoryState","observations","repositoryEvidence"],"description":"Complete R=16 segment plus next-segment-first-key probe at one signed head. startRevision is 1+16*k; exactly 17 ordered observations cover startRevision..startRevision+16 without gaps, duplicates or truncation. If the segment's last revision is present, read the next complete segment before a final prefix is reported. A visible present key above an absence is integrity. priorPrefix is absent for the first segment and required for a later one with fully authenticated prior coverage at the same head. A later-window response carries only the final window and priorPrefix terminal block/link: a response-local consumer can independently recompute those, while earlier-window coverage rests on the qualified acquisition adapter's authenticated same-head prior coverage. Full-chain independent verification requires every earlier authenticated window, which this response does not carry.","properties":{"startRevision":{"type":"integer","minimum":1,"maximum":9007199254740991},"repositoryState":{"type":"string","minLength":1,"maxLength":2048,"description":"Opaque authenticated repository-state identity. Profile validation retains the existing 1..512 UTF-16-code-unit Unicode-scalar bound; all observations for one authority use exactly this same state. This label alone authenticates nothing."},"observations":{"type":"array","minLength":17,"maxLength":17,"items":{"type":"union","refs":["#lifecyclePresent","#lifecycleAbsent"]}},"repositoryEvidence":{"type":"ref","ref":"#repositoryEvidence"},"priorPrefix":{"type":"ref","ref":"#priorPrefix"}}},"lifecycleSource":{"type":"object","required":["id","kind","repositoryState","throughRevision"],"description":"Qualified currentness source, independently checked against the operator's pinned source configuration and retained evidence. gap-free requires uninterrupted ingestion from path genesis plus sticky integrity/high-water continuity. complete-exhaustion requires authenticated complete enumeration of the path at this head. Identity, kind, state and throughRevision must all match; an unverifiable qualification grants no current claim.","properties":{"id":{"type":"string","minLength":1,"maxLength":2048,"description":"Exact operator-qualified source identifier, bounded by the profile to 512 UTF-16 code units. Caller-supplied names never qualify a source."},"kind":{"type":"string","knownValues":["gap-free","complete-exhaustion"],"maxLength":64},"repositoryState":{"type":"string","minLength":1,"maxLength":2048,"description":"Opaque authenticated repository-state identity. Profile validation retains the existing 1..512 UTF-16-code-unit Unicode-scalar bound; all observations for one authority use exactly this same state. This label alone authenticates nothing."},"throughRevision":{"type":"integer","minimum":0,"maximum":9007199254740991}}},"lifecyclePrefix":{"type":"object","required":["throughRevision"],"description":"Authenticated contiguous lower bound through this revision at the window head, not current published status. Zero means no genesis was proved. Display/reconciliation only; this result cannot authorize an effect or be promoted to current from a finite absent suffix.","properties":{"throughRevision":{"type":"integer","minimum":0,"maximum":9007199254740991}}},"lifecycleCurrent":{"type":"object","required":["throughRevision","source"],"description":"Current published chain through this revision established by the named qualified source, with complete observation/window verification. Source throughRevision equals this value. This remains eventual public evidence, never sole real-time payment or entitlement authority. The verifier rejects an unqualified currentSource as invalid input rather than silently downgrading it. A downstream consumer receiving a current result whose source qualification it cannot establish treats otherwise validated window evidence only as a prefix; invalid window evidence cannot be salvaged this way.","properties":{"throughRevision":{"type":"integer","minimum":0,"maximum":9007199254740991},"source":{"type":"ref","ref":"#lifecycleSource"}}},"retracted":{"type":"object","required":["author","receipt","retraction","block","record","evidenceAsOf"],"description":"Authenticated author retracted this exact receipt generation at its co-located deterministic retraction key. The receipt is not republished, replaced or deleted by this act; prior public copies remain public. Consumers validate the retraction block, record, author/location and both exact strongRefs. No settlement or entitlement authority is granted.","properties":{"author":{"type":"string","format":"did"},"receipt":{"type":"ref","ref":"com.atproto.repo.strongRef"},"retraction":{"type":"ref","ref":"com.atproto.repo.strongRef"},"block":{"type":"ref","ref":"#blockEvidence"},"record":{"type":"unknown","description":"Exact decoded receiptRetraction record, validated against the returned block and exact receipt strongRef."},"evidenceAsOf":{"type":"string","format":"datetime"}}},"retractionInvalid":{"type":"object","required":["retraction","block","evidenceAsOf"],"description":"Authenticated record at the deterministic retraction key is invalid or does not name the requested exact receipt generation. Fail closed; this does not prove a valid author withdrawal or permit ordinary current success. Malformed decoded content is not echoed.","properties":{"retraction":{"type":"ref","ref":"com.atproto.repo.strongRef"},"block":{"type":"ref","ref":"#blockEvidence"},"evidenceAsOf":{"type":"string","format":"datetime"}}}}}