{
  "$schema": "https://json-schema.org/draft/2020-12/schema",
  "$id": "https://thehiveryiq.com/.well-known/schemas/delivered-set-containment-v1.json",
  "title": "Delivered Set Containment Receipt, v1",
  "description": "Canonical schema for the Hive delivered set containment receipt, canonical type delivered.set.containment. The instrument records, by salted fingerprint Merkle roots only, an entitled set committed before a delivery window opened and the set of instruments and fields delivered in that window, together with the service computed count of delivered items inside and outside the entitled set. No identifier enters the signed body.",
  "type": "object",
  "required": [
    "receipt_id",
    "payload_sha256",
    "sig_b64u",
    "key_id",
    "algorithm",
    "ts",
    "signed_body"
  ],
  "additionalProperties": false,
  "properties": {
    "receipt_id": {
      "type": "string",
      "pattern": "^r_delivered[.]set[.]containment_[0-9]{10,}_[0-9a-f]{12}$"
    },
    "payload_sha256": {
      "type": "string",
      "pattern": "^[0-9a-f]{64}$"
    },
    "sig_b64u": {
      "type": "string",
      "pattern": "^[A-Za-z0-9_-]{86}$"
    },
    "key_id": {
      "type": "string",
      "pattern": "^did:(hive|web|key):[A-Za-z0-9._:%-]+$"
    },
    "algorithm": {
      "type": "string",
      "const": "Ed25519"
    },
    "ts": {
      "type": "integer",
      "minimum": 1000000000
    },
    "signed_body": {
      "type": "object",
      "required": [
        "receipt_type",
        "schema",
        "window_id",
        "window",
        "entitlement",
        "delivered",
        "finding",
        "salt_commitment",
        "recipient_commitment",
        "recorded_at",
        "boundary"
      ],
      "additionalProperties": false,
      "properties": {
        "receipt_type": {
          "type": "string",
          "const": "delivered.set.containment"
        },
        "schema": {
          "type": "string",
          "const": "r1.0.0"
        },
        "window_id": {
          "type": "string",
          "pattern": "^win_[0-9a-z][0-9a-z._-]{0,63}$"
        },
        "window": {
          "type": "object",
          "required": [
            "start",
            "end"
          ],
          "additionalProperties": false,
          "properties": {
            "start": {
              "type": "object",
              "required": [
                "utc",
                "drift_seconds"
              ],
              "additionalProperties": false,
              "properties": {
                "utc": {
                  "type": "string",
                  "pattern": "^[0-9]{4}-[0-9]{2}-[0-9]{2}T[0-9]{2}:[0-9]{2}:[0-9]{2}([.][0-9]{1,9})?Z$"
                },
                "drift_seconds": {
                  "type": "integer",
                  "minimum": 0,
                  "maximum": 86400
                }
              }
            },
            "end": {
              "type": "object",
              "required": [
                "utc",
                "drift_seconds"
              ],
              "additionalProperties": false,
              "properties": {
                "utc": {
                  "type": "string",
                  "pattern": "^[0-9]{4}-[0-9]{2}-[0-9]{2}T[0-9]{2}:[0-9]{2}:[0-9]{2}([.][0-9]{1,9})?Z$"
                },
                "drift_seconds": {
                  "type": "integer",
                  "minimum": 0,
                  "maximum": 86400
                }
              }
            }
          }
        },
        "entitlement": {
          "type": "object",
          "required": [
            "set_root",
            "set_size",
            "committed_at"
          ],
          "additionalProperties": false,
          "properties": {
            "set_root": {
              "type": "string",
              "pattern": "^[0-9a-f]{64}$",
              "description": "Merkle root over the sorted, deduplicated salted fingerprints of the entitled instruments and fields."
            },
            "set_size": {
              "type": "integer",
              "minimum": 0,
              "maximum": 1000000
            },
            "committed_at": {
              "type": "object",
              "required": [
                "utc",
                "drift_seconds"
              ],
              "additionalProperties": false,
              "properties": {
                "utc": {
                  "type": "string",
                  "pattern": "^[0-9]{4}-[0-9]{2}-[0-9]{2}T[0-9]{2}:[0-9]{2}:[0-9]{2}([.][0-9]{1,9})?Z$"
                },
                "drift_seconds": {
                  "type": "integer",
                  "minimum": 0,
                  "maximum": 86400
                }
              }
            }
          }
        },
        "delivered": {
          "type": "object",
          "required": [
            "set_root",
            "set_size"
          ],
          "additionalProperties": false,
          "properties": {
            "set_root": {
              "type": "string",
              "pattern": "^[0-9a-f]{64}$",
              "description": "Merkle root over the sorted, deduplicated salted fingerprints of the delivered instruments and fields."
            },
            "set_size": {
              "type": "integer",
              "minimum": 0,
              "maximum": 1000000
            }
          }
        },
        "finding": {
          "type": "object",
          "required": [
            "inside_count",
            "outside_count",
            "containment_relation"
          ],
          "additionalProperties": false,
          "properties": {
            "inside_count": {
              "type": "integer",
              "minimum": 0,
              "maximum": 1000000
            },
            "outside_count": {
              "type": "integer",
              "minimum": 0,
              "maximum": 1000000
            },
            "containment_relation": {
              "type": "string",
              "enum": [
                "delivered_within_entitled_set",
                "delivered_outside_entitled_set"
              ]
            }
          }
        },
        "salt_commitment": {
          "type": "string",
          "pattern": "^[0-9a-f]{64}$"
        },
        "recipient_commitment": {
          "type": "string",
          "pattern": "^[0-9a-f]{64}$",
          "description": "Salted commitment over the recipient descriptor. No recipient is named here."
        },
        "recorded_at": {
          "type": "object",
          "required": [
            "utc",
            "drift_seconds"
          ],
          "additionalProperties": false,
          "properties": {
            "utc": {
              "type": "string",
              "pattern": "^[0-9]{4}-[0-9]{2}-[0-9]{2}T[0-9]{2}:[0-9]{2}:[0-9]{2}([.][0-9]{1,9})?Z$"
            },
            "drift_seconds": {
              "type": "integer",
              "minimum": 0,
              "maximum": 86400
            }
          }
        },
        "boundary": {
          "type": "string",
          "minLength": 1,
          "const": "This receipt records only that Hive computed, from salted fingerprints, how many of the instruments and fields delivered in the named window sat inside and how many sat outside an entitled fingerprint set whose root was recorded as committed before the window opened, and that a verifier holding the disclosed fingerprint sets can recompute those roots and that count. Hive records and checks; it does not decide, block, enforce or sit in the access path. It does not establish that the entitled set reflects any agreement, that the delivered set is complete, that any delivery was or was not permitted, or that any party acted on this count. A receipt shows what was recorded and when, not that it was correct. The identifiers behind the fingerprints, including those of any item outside the entitled set, never enter this receipt, and the recorded instants are presented as reported by the recording party."
        }
      }
    }
  }
}
