{
  "$schema": "https://json-schema.org/draft/2020-12/schema",
  "$id": "https://github.com/mieweb/pulsevault/blob/main/protocol/schemas/capability-token.schema.json",
  "title": "Capability token claims",
  "description": "The claims inside a capability token (PROTOCOL.md §5.4). The token is `base64url(JSON claims).signature`, HMAC-signed by the issuing deployment. It authorizes the artifact it names and any artifact whose `relatedTo` is that artifact.",
  "type": "object",
  "required": ["artifactId", "iat", "exp", "kid", "issuer"],
  "properties": {
    "artifactId": {
      "type": "string",
      "format": "uuid",
      "description": "The artifact the token is for (the pulse's video)."
    },
    "iat": {
      "type": "integer",
      "description": "Issued at, in seconds since the Unix epoch."
    },
    "exp": {
      "type": "integer",
      "description": "Expires at, in seconds since the Unix epoch."
    },
    "kid": {
      "type": "string",
      "description": "Id of the signing key, so a deployment can rotate secrets."
    },
    "issuer": {
      "type": "string",
      "description": "The issuing deployment. A token from another issuer is rejected."
    },
    "use": {
      "type": "string",
      "enum": ["view"],
      "description": "`view` on a read-only view token (§5.5), which only opens artifacts and is signed with a key derived from the secret. Absent on the capability token an upload uses."
    },
    "ctx": {
      "description": "Opaque host data signed into the token (protocol 2.3): who the upload is for, where it goes. The server stores it with the artifact the token creates and hands it back to its own hooks; a client never reads it. Any JSON, at most 1 KiB encoded."
    }
  }
}
