{
  "$schema": "https://json-schema.org/draft/2020-12/schema",
  "type": "object",
  "properties": {
    "format": {
      "type": "string",
      "const": "aih-policy-authority-receipt"
    },
    "version": {
      "type": "number",
      "const": 1
    },
    "issuerRepository": {
      "type": "string",
      "pattern": "^[A-Za-z0-9_.-]+\\/[A-Za-z0-9_.-]+$"
    },
    "issuedAt": {
      "type": "string"
    },
    "expiresAt": {
      "type": "string"
    },
    "trustedIssuers": {
      "default": [],
      "type": "array",
      "items": {
        "type": "object",
        "properties": {
          "id": {
            "type": "string",
            "pattern": "^[a-z][a-z0-9-]{0,63}$"
          },
          "githubRepository": {
            "type": "string",
            "pattern": "^[A-Za-z0-9_.-]+\\/[A-Za-z0-9_.-]+$"
          }
        },
        "required": [
          "id",
          "githubRepository"
        ],
        "additionalProperties": false
      }
    },
    "evidence": {
      "type": "array",
      "items": {
        "type": "object",
        "properties": {
          "id": {
            "type": "string",
            "pattern": "^[a-z][a-z0-9-]{0,63}$"
          },
          "candidate": {
            "type": "string",
            "pattern": "^[a-z][a-z0-9-]{0,63}$"
          },
          "kind": {
            "type": "string",
            "enum": [
              "mcp",
              "hook",
              "framework"
            ]
          },
          "source": {
            "anyOf": [
              {
                "type": "object",
                "properties": {
                  "type": {
                    "type": "string",
                    "const": "git"
                  },
                  "repository": {
                    "type": "string",
                    "pattern": "^[A-Za-z0-9_.-]+\\/[A-Za-z0-9_.-]+$"
                  },
                  "commit": {
                    "type": "string",
                    "pattern": "^[0-9a-f]{40}$"
                  },
                  "tree": {
                    "type": "string",
                    "pattern": "^[0-9a-f]{40}$"
                  }
                },
                "required": [
                  "type",
                  "repository",
                  "commit",
                  "tree"
                ],
                "additionalProperties": false
              },
              {
                "type": "object",
                "properties": {
                  "type": {
                    "type": "string",
                    "const": "package"
                  },
                  "registry": {
                    "type": "string",
                    "pattern": "^https:\\/\\/[A-Za-z0-9](?:[A-Za-z0-9.-]{0,251}[A-Za-z0-9])?(?::(?:[0-9]|[1-9][0-9]{1,3}|[1-5][0-9]{4}|6[0-4][0-9]{3}|65[0-4][0-9]{2}|655[0-2][0-9]|6553[0-5]))?$"
                  },
                  "package": {
                    "type": "string",
                    "pattern": "^@?[A-Za-z0-9][A-Za-z0-9._/-]*$"
                  },
                  "version": {
                    "type": "string",
                    "pattern": "^(0|[1-9][0-9]*)\\.(0|[1-9][0-9]*)\\.(0|[1-9][0-9]*)(?:-[0-9A-Za-z.-]+)?$"
                  },
                  "integrity": {
                    "type": "string",
                    "pattern": "^sha256:[0-9a-f]{64}$"
                  }
                },
                "required": [
                  "type",
                  "registry",
                  "package",
                  "version",
                  "integrity"
                ],
                "additionalProperties": false
              },
              {
                "type": "object",
                "properties": {
                  "type": {
                    "type": "string",
                    "const": "command"
                  },
                  "command": {
                    "type": "string",
                    "minLength": 1,
                    "maxLength": 200,
                    "pattern": "^[A-Za-z0-9][A-Za-z0-9._@:+-]*$"
                  },
                  "args": {
                    "default": [],
                    "type": "array",
                    "items": {
                      "type": "string",
                      "minLength": 1,
                      "maxLength": 500
                    }
                  },
                  "executableDigest": {
                    "type": "string",
                    "pattern": "^sha256:[0-9a-f]{64}$"
                  }
                },
                "required": [
                  "type",
                  "command",
                  "executableDigest"
                ],
                "additionalProperties": false
              },
              {
                "type": "object",
                "properties": {
                  "type": {
                    "type": "string",
                    "const": "stdio"
                  },
                  "resolver": {
                    "type": "string",
                    "enum": [
                      "npx",
                      "uvx"
                    ]
                  },
                  "registry": {
                    "type": "string",
                    "pattern": "^https:\\/\\/[A-Za-z0-9](?:[A-Za-z0-9.-]{0,251}[A-Za-z0-9])?(?::(?:[0-9]|[1-9][0-9]{1,3}|[1-5][0-9]{4}|6[0-4][0-9]{3}|65[0-4][0-9]{2}|655[0-2][0-9]|6553[0-5]))?$"
                  },
                  "package": {
                    "type": "string",
                    "pattern": "^@?[A-Za-z0-9][A-Za-z0-9._/-]*$"
                  },
                  "version": {
                    "type": "string",
                    "pattern": "^(0|[1-9][0-9]*)\\.(0|[1-9][0-9]*)\\.(0|[1-9][0-9]*)(?:-[0-9A-Za-z.-]+)?$"
                  },
                  "integrity": {
                    "type": "string",
                    "pattern": "^sha256:[0-9a-f]{64}$"
                  }
                },
                "required": [
                  "type",
                  "resolver",
                  "registry",
                  "package",
                  "version",
                  "integrity"
                ],
                "additionalProperties": false
              },
              {
                "anyOf": [
                  {
                    "type": "object",
                    "properties": {
                      "type": {
                        "type": "string",
                        "const": "remote"
                      },
                      "origin": {
                        "type": "string",
                        "pattern": "^https:\\/\\/[A-Za-z0-9](?:[A-Za-z0-9.-]{0,251}[A-Za-z0-9])?(?::(?:[0-9]|[1-9][0-9]{1,3}|[1-5][0-9]{4}|6[0-4][0-9]{3}|65[0-4][0-9]{2}|655[0-2][0-9]|6553[0-5]))?$"
                      },
                      "approval": {
                        "type": "object",
                        "properties": {
                          "approvedBy": {
                            "type": "string",
                            "pattern": "^[a-z][a-z0-9-]{0,63}$"
                          },
                          "authenticationMode": {
                            "type": "string",
                            "minLength": 1,
                            "maxLength": 500
                          },
                          "allowedDataClasses": {
                            "minItems": 1,
                            "maxItems": 20,
                            "type": "array",
                            "items": {
                              "type": "string",
                              "pattern": "^[a-z][a-z0-9-]{0,63}$"
                            }
                          }
                        },
                        "required": [
                          "approvedBy",
                          "authenticationMode",
                          "allowedDataClasses"
                        ],
                        "additionalProperties": false
                      },
                      "contentScanned": {
                        "type": "boolean",
                        "const": false
                      },
                      "administrativeStatus": {
                        "type": "string",
                        "enum": [
                          "approved",
                          "revoked"
                        ]
                      }
                    },
                    "required": [
                      "type",
                      "origin",
                      "approval",
                      "contentScanned",
                      "administrativeStatus"
                    ],
                    "additionalProperties": false
                  },
                  {
                    "type": "object",
                    "properties": {
                      "type": {
                        "type": "string",
                        "const": "remote"
                      },
                      "origin": {
                        "type": "string",
                        "pattern": "^https:\\/\\/[A-Za-z0-9](?:[A-Za-z0-9.-]{0,251}[A-Za-z0-9])?(?::(?:[0-9]|[1-9][0-9]{1,3}|[1-5][0-9]{4}|6[0-4][0-9]{3}|65[0-4][0-9]{2}|655[0-2][0-9]|6553[0-5]))?$"
                      },
                      "approval": {
                        "type": "object",
                        "properties": {
                          "approvedBy": {
                            "type": "string",
                            "pattern": "^[a-z][a-z0-9-]{0,63}$"
                          },
                          "authenticationMode": {
                            "type": "string",
                            "minLength": 1,
                            "maxLength": 500
                          },
                          "allowedDataClasses": {
                            "minItems": 1,
                            "maxItems": 20,
                            "type": "array",
                            "items": {
                              "type": "string",
                              "pattern": "^[a-z][a-z0-9-]{0,63}$"
                            }
                          }
                        },
                        "required": [
                          "approvedBy",
                          "authenticationMode",
                          "allowedDataClasses"
                        ],
                        "additionalProperties": false
                      },
                      "contentScanned": {
                        "type": "boolean",
                        "const": false
                      },
                      "toolSurfaceDigest": {
                        "type": "string",
                        "pattern": "^sha256:[0-9a-f]{64}$"
                      },
                      "verdict": {
                        "type": "string",
                        "enum": [
                          "approved",
                          "drifted",
                          "revoked"
                        ]
                      }
                    },
                    "required": [
                      "type",
                      "origin",
                      "approval",
                      "contentScanned",
                      "toolSurfaceDigest",
                      "verdict"
                    ],
                    "additionalProperties": false
                  }
                ]
              },
              {
                "type": "object",
                "properties": {
                  "type": {
                    "type": "string",
                    "const": "mcp"
                  },
                  "server": {
                    "type": "string",
                    "pattern": "^[a-z][a-z0-9-]{0,63}$"
                  },
                  "subject": {
                    "type": "string",
                    "pattern": "^mcp-server-sha256:[0-9a-f]{64}$"
                  }
                },
                "required": [
                  "type",
                  "server",
                  "subject"
                ],
                "additionalProperties": false
              },
              {
                "type": "object",
                "properties": {
                  "type": {
                    "type": "string",
                    "const": "hook"
                  },
                  "handler": {
                    "type": "string",
                    "const": "usage-metering"
                  },
                  "scriptDigest": {
                    "type": "string",
                    "pattern": "^sha256:[0-9a-f]{64}$"
                  }
                },
                "required": [
                  "type",
                  "handler",
                  "scriptDigest"
                ],
                "additionalProperties": false
              }
            ]
          },
          "sourceDigest": {
            "type": "string",
            "pattern": "^sha256:[0-9a-f]{64}$"
          },
          "evidenceDigest": {
            "type": "string",
            "pattern": "^sha256:[0-9a-f]{64}$"
          },
          "identityDigest": {
            "type": "string",
            "pattern": "^sha256:[0-9a-f]{64}$"
          },
          "state": {
            "type": "string",
            "enum": [
              "verified",
              "missing",
              "failed"
            ]
          },
          "waivable": {
            "type": "boolean"
          },
          "detectors": {
            "default": [],
            "type": "array",
            "items": {
              "type": "object",
              "properties": {
                "id": {
                  "type": "string",
                  "pattern": "^[a-z][a-z0-9-]{0,63}$"
                },
                "required": {
                  "type": "boolean"
                },
                "status": {
                  "type": "string",
                  "enum": [
                    "pass",
                    "missing",
                    "fail"
                  ]
                },
                "reportDigest": {
                  "type": "string",
                  "pattern": "^sha256:[0-9a-f]{64}$"
                }
              },
              "required": [
                "id",
                "required",
                "status"
              ],
              "additionalProperties": false
            }
          },
          "findings": {
            "default": [],
            "type": "array",
            "items": {
              "type": "string",
              "enum": [
                "malicious-code",
                "prompt-injection",
                "auto-executing-hook",
                "hidden-unicode",
                "secrets",
                "unpinned-source",
                "dependency-confusion",
                "mandatory-detector-failed",
                "evidence-identity-drift",
                "unsafe-path",
                "normalized-collision",
                "missing-projector",
                "unsupported-target",
                "ownership-conflict"
              ]
            }
          }
        },
        "required": [
          "id",
          "candidate",
          "kind",
          "source",
          "sourceDigest",
          "evidenceDigest",
          "identityDigest",
          "state",
          "waivable"
        ],
        "additionalProperties": false
      }
    },
    "approvals": {
      "type": "array",
      "items": {
        "type": "object",
        "properties": {
          "id": {
            "type": "string",
            "pattern": "^[a-z][a-z0-9-]{0,63}$"
          },
          "candidate": {
            "type": "string",
            "pattern": "^[a-z][a-z0-9-]{0,63}$"
          },
          "kind": {
            "type": "string",
            "enum": [
              "mcp",
              "hook",
              "framework"
            ]
          },
          "source": {
            "anyOf": [
              {
                "type": "object",
                "properties": {
                  "type": {
                    "type": "string",
                    "const": "git"
                  },
                  "repository": {
                    "type": "string",
                    "pattern": "^[A-Za-z0-9_.-]+\\/[A-Za-z0-9_.-]+$"
                  },
                  "commit": {
                    "type": "string",
                    "pattern": "^[0-9a-f]{40}$"
                  },
                  "tree": {
                    "type": "string",
                    "pattern": "^[0-9a-f]{40}$"
                  }
                },
                "required": [
                  "type",
                  "repository",
                  "commit",
                  "tree"
                ],
                "additionalProperties": false
              },
              {
                "type": "object",
                "properties": {
                  "type": {
                    "type": "string",
                    "const": "package"
                  },
                  "registry": {
                    "type": "string",
                    "pattern": "^https:\\/\\/[A-Za-z0-9](?:[A-Za-z0-9.-]{0,251}[A-Za-z0-9])?(?::(?:[0-9]|[1-9][0-9]{1,3}|[1-5][0-9]{4}|6[0-4][0-9]{3}|65[0-4][0-9]{2}|655[0-2][0-9]|6553[0-5]))?$"
                  },
                  "package": {
                    "type": "string",
                    "pattern": "^@?[A-Za-z0-9][A-Za-z0-9._/-]*$"
                  },
                  "version": {
                    "type": "string",
                    "pattern": "^(0|[1-9][0-9]*)\\.(0|[1-9][0-9]*)\\.(0|[1-9][0-9]*)(?:-[0-9A-Za-z.-]+)?$"
                  },
                  "integrity": {
                    "type": "string",
                    "pattern": "^sha256:[0-9a-f]{64}$"
                  }
                },
                "required": [
                  "type",
                  "registry",
                  "package",
                  "version",
                  "integrity"
                ],
                "additionalProperties": false
              },
              {
                "type": "object",
                "properties": {
                  "type": {
                    "type": "string",
                    "const": "command"
                  },
                  "command": {
                    "type": "string",
                    "minLength": 1,
                    "maxLength": 200,
                    "pattern": "^[A-Za-z0-9][A-Za-z0-9._@:+-]*$"
                  },
                  "args": {
                    "default": [],
                    "type": "array",
                    "items": {
                      "type": "string",
                      "minLength": 1,
                      "maxLength": 500
                    }
                  },
                  "executableDigest": {
                    "type": "string",
                    "pattern": "^sha256:[0-9a-f]{64}$"
                  }
                },
                "required": [
                  "type",
                  "command",
                  "executableDigest"
                ],
                "additionalProperties": false
              },
              {
                "type": "object",
                "properties": {
                  "type": {
                    "type": "string",
                    "const": "stdio"
                  },
                  "resolver": {
                    "type": "string",
                    "enum": [
                      "npx",
                      "uvx"
                    ]
                  },
                  "registry": {
                    "type": "string",
                    "pattern": "^https:\\/\\/[A-Za-z0-9](?:[A-Za-z0-9.-]{0,251}[A-Za-z0-9])?(?::(?:[0-9]|[1-9][0-9]{1,3}|[1-5][0-9]{4}|6[0-4][0-9]{3}|65[0-4][0-9]{2}|655[0-2][0-9]|6553[0-5]))?$"
                  },
                  "package": {
                    "type": "string",
                    "pattern": "^@?[A-Za-z0-9][A-Za-z0-9._/-]*$"
                  },
                  "version": {
                    "type": "string",
                    "pattern": "^(0|[1-9][0-9]*)\\.(0|[1-9][0-9]*)\\.(0|[1-9][0-9]*)(?:-[0-9A-Za-z.-]+)?$"
                  },
                  "integrity": {
                    "type": "string",
                    "pattern": "^sha256:[0-9a-f]{64}$"
                  }
                },
                "required": [
                  "type",
                  "resolver",
                  "registry",
                  "package",
                  "version",
                  "integrity"
                ],
                "additionalProperties": false
              },
              {
                "anyOf": [
                  {
                    "type": "object",
                    "properties": {
                      "type": {
                        "type": "string",
                        "const": "remote"
                      },
                      "origin": {
                        "type": "string",
                        "pattern": "^https:\\/\\/[A-Za-z0-9](?:[A-Za-z0-9.-]{0,251}[A-Za-z0-9])?(?::(?:[0-9]|[1-9][0-9]{1,3}|[1-5][0-9]{4}|6[0-4][0-9]{3}|65[0-4][0-9]{2}|655[0-2][0-9]|6553[0-5]))?$"
                      },
                      "approval": {
                        "type": "object",
                        "properties": {
                          "approvedBy": {
                            "type": "string",
                            "pattern": "^[a-z][a-z0-9-]{0,63}$"
                          },
                          "authenticationMode": {
                            "type": "string",
                            "minLength": 1,
                            "maxLength": 500
                          },
                          "allowedDataClasses": {
                            "minItems": 1,
                            "maxItems": 20,
                            "type": "array",
                            "items": {
                              "type": "string",
                              "pattern": "^[a-z][a-z0-9-]{0,63}$"
                            }
                          }
                        },
                        "required": [
                          "approvedBy",
                          "authenticationMode",
                          "allowedDataClasses"
                        ],
                        "additionalProperties": false
                      },
                      "contentScanned": {
                        "type": "boolean",
                        "const": false
                      },
                      "administrativeStatus": {
                        "type": "string",
                        "enum": [
                          "approved",
                          "revoked"
                        ]
                      }
                    },
                    "required": [
                      "type",
                      "origin",
                      "approval",
                      "contentScanned",
                      "administrativeStatus"
                    ],
                    "additionalProperties": false
                  },
                  {
                    "type": "object",
                    "properties": {
                      "type": {
                        "type": "string",
                        "const": "remote"
                      },
                      "origin": {
                        "type": "string",
                        "pattern": "^https:\\/\\/[A-Za-z0-9](?:[A-Za-z0-9.-]{0,251}[A-Za-z0-9])?(?::(?:[0-9]|[1-9][0-9]{1,3}|[1-5][0-9]{4}|6[0-4][0-9]{3}|65[0-4][0-9]{2}|655[0-2][0-9]|6553[0-5]))?$"
                      },
                      "approval": {
                        "type": "object",
                        "properties": {
                          "approvedBy": {
                            "type": "string",
                            "pattern": "^[a-z][a-z0-9-]{0,63}$"
                          },
                          "authenticationMode": {
                            "type": "string",
                            "minLength": 1,
                            "maxLength": 500
                          },
                          "allowedDataClasses": {
                            "minItems": 1,
                            "maxItems": 20,
                            "type": "array",
                            "items": {
                              "type": "string",
                              "pattern": "^[a-z][a-z0-9-]{0,63}$"
                            }
                          }
                        },
                        "required": [
                          "approvedBy",
                          "authenticationMode",
                          "allowedDataClasses"
                        ],
                        "additionalProperties": false
                      },
                      "contentScanned": {
                        "type": "boolean",
                        "const": false
                      },
                      "toolSurfaceDigest": {
                        "type": "string",
                        "pattern": "^sha256:[0-9a-f]{64}$"
                      },
                      "verdict": {
                        "type": "string",
                        "enum": [
                          "approved",
                          "drifted",
                          "revoked"
                        ]
                      }
                    },
                    "required": [
                      "type",
                      "origin",
                      "approval",
                      "contentScanned",
                      "toolSurfaceDigest",
                      "verdict"
                    ],
                    "additionalProperties": false
                  }
                ]
              },
              {
                "type": "object",
                "properties": {
                  "type": {
                    "type": "string",
                    "const": "mcp"
                  },
                  "server": {
                    "type": "string",
                    "pattern": "^[a-z][a-z0-9-]{0,63}$"
                  },
                  "subject": {
                    "type": "string",
                    "pattern": "^mcp-server-sha256:[0-9a-f]{64}$"
                  }
                },
                "required": [
                  "type",
                  "server",
                  "subject"
                ],
                "additionalProperties": false
              },
              {
                "type": "object",
                "properties": {
                  "type": {
                    "type": "string",
                    "const": "hook"
                  },
                  "handler": {
                    "type": "string",
                    "const": "usage-metering"
                  },
                  "scriptDigest": {
                    "type": "string",
                    "pattern": "^sha256:[0-9a-f]{64}$"
                  }
                },
                "required": [
                  "type",
                  "handler",
                  "scriptDigest"
                ],
                "additionalProperties": false
              }
            ]
          },
          "issuer": {
            "type": "string",
            "pattern": "^[a-z][a-z0-9-]{0,63}$"
          },
          "sourceDigest": {
            "type": "string",
            "pattern": "^sha256:[0-9a-f]{64}$"
          },
          "evidenceDigest": {
            "type": "string",
            "pattern": "^sha256:[0-9a-f]{64}$"
          },
          "projector": {
            "type": "string",
            "enum": [
              "mcp-managed-settings",
              "hook-managed-settings",
              "usage-hook",
              "framework-contract"
            ]
          },
          "policyVersion": {
            "type": "string",
            "minLength": 1,
            "maxLength": 500
          },
          "reason": {
            "type": "string",
            "minLength": 1,
            "maxLength": 500
          },
          "clarification": {
            "type": "string",
            "minLength": 1,
            "maxLength": 500
          },
          "scope": {
            "minItems": 1,
            "maxItems": 3,
            "type": "array",
            "items": {
              "type": "string",
              "enum": [
                "claude",
                "codex",
                "kiro"
              ]
            }
          },
          "notBefore": {
            "type": "string"
          },
          "expiresAt": {
            "type": "string"
          },
          "github": {
            "type": "object",
            "properties": {
              "repository": {
                "type": "string",
                "pattern": "^[A-Za-z0-9_.-]+\\/[A-Za-z0-9_.-]+$"
              },
              "attestationId": {
                "type": "string",
                "minLength": 1,
                "maxLength": 500
              },
              "subjectDigest": {
                "type": "string",
                "pattern": "^sha256:[0-9a-f]{64}$"
              }
            },
            "required": [
              "repository",
              "attestationId",
              "subjectDigest"
            ],
            "additionalProperties": false
          }
        },
        "required": [
          "id",
          "candidate",
          "kind",
          "source",
          "issuer",
          "sourceDigest",
          "evidenceDigest",
          "projector",
          "policyVersion",
          "reason",
          "scope",
          "notBefore",
          "expiresAt",
          "github"
        ],
        "additionalProperties": false
      }
    },
    "revocations": {
      "default": [],
      "type": "array",
      "items": {
        "type": "object",
        "properties": {
          "approval": {
            "type": "string",
            "pattern": "^[a-z][a-z0-9-]{0,63}$"
          },
          "issuer": {
            "type": "string",
            "pattern": "^[a-z][a-z0-9-]{0,63}$"
          },
          "revokedAt": {
            "type": "string"
          },
          "reason": {
            "type": "string",
            "minLength": 1,
            "maxLength": 500
          }
        },
        "required": [
          "approval",
          "issuer",
          "revokedAt",
          "reason"
        ],
        "additionalProperties": false
      }
    },
    "targets": {
      "minItems": 1,
      "maxItems": 3,
      "type": "array",
      "items": {
        "type": "string",
        "enum": [
          "claude",
          "codex",
          "kiro"
        ]
      }
    }
  },
  "required": [
    "format",
    "version",
    "issuerRepository",
    "issuedAt",
    "expiresAt",
    "targets"
  ],
  "additionalProperties": false,
  "title": ".aih/policy-authority-receipt.json"
}
