{
  "openapi": "3.1.0",
  "info": {
    "title": "mandate-sts",
    "summary": "Planned deployment boundary; exact domain-to-library responsibilities and required adapter/worker gaps are recorded in docs/architecture/ownership.md.",
    "description": "The HTTP surface of `mandate-sts`, one of the components of `mandate` v1.\n\nEvery path here is one semantic command, so the method is always POST and the path is the command's wire name under its domain's: a command is not a resource, and this document does not invent one. A status code is the outcome the specification declares — 202 for a branch that was taken, 422 for a refusal the input decides, 502 for a refusal decided outside the request — and the `outcome` property of every response body names the branch. Events emitted by a branch are published to consumers through the event transport; they are not returned here.",
    "version": "v1",
    "x-ess-provenance": {
      "system": "mandate",
      "specification_version": "v1",
      "source_digest": "2f11d2daffc2d75bb4ca8c0485aedc56fb2a712cdaed6347fc48b8ba2b1f7ca6",
      "contract_digest": "slice-sha256/2:16ece1d4629a99c4f705b32b6556efd9819560f0cd5b4b0de160e77dadd5ceb5"
    }
  },
  "tags": [
    {
      "name": "credential"
    }
  ],
  "paths": {
    "/credential/commands/DisableResourceServer": {
      "post": {
        "operationId": "mandate.credential.DisableResourceServer",
        "summary": "DisableResourceServer",
        "tags": [
          "credential"
        ],
        "requestBody": {
          "description": "The input `mandate.credential.DisableResourceServer` declares.",
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/mandate.credential.DisableResourceServer.Input"
              }
            }
          }
        },
        "responses": {
          "202": {
            "description": "Outcome `accepted`: the branch the specification declares for this input. Events this branch emits are published to consumers, not returned here.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/mandate.credential.DisableResourceServer.accepted.Response"
                }
              }
            }
          },
          "409": {
            "description": "Outcome `wrong-state`: the input was acceptable and the subject is in a state this command does not act from. Resending the same request changes nothing until something else moves it.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/mandate.credential.DisableResourceServer.wrong-state.Response"
                }
              }
            }
          },
          "502": {
            "description": "Outcome `denied`: something outside the request refused. The input was acceptable, so the caller has nothing to correct and a retry is meaningful.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/mandate.credential.DisableResourceServer.denied.Response"
                }
              }
            }
          }
        }
      }
    },
    "/credential/commands/ExchangeCredential": {
      "post": {
        "operationId": "mandate.credential.ExchangeCredential",
        "summary": "ExchangeCredential",
        "tags": [
          "credential"
        ],
        "requestBody": {
          "description": "The input `mandate.credential.ExchangeCredential` declares.",
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/mandate.credential.ExchangeCredential.Input"
              }
            }
          }
        },
        "responses": {
          "202": {
            "description": "Outcome `accepted`: the branch the specification declares for this input. Events this branch emits are published to consumers, not returned here.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/mandate.credential.ExchangeCredential.accepted.Response"
                }
              }
            }
          },
          "502": {
            "description": "Outcome `denied`: something outside the request refused. The input was acceptable, so the caller has nothing to correct and a retry is meaningful.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/mandate.credential.ExchangeCredential.denied.Response"
                }
              }
            }
          }
        }
      }
    },
    "/credential/commands/IntrospectCredential": {
      "post": {
        "operationId": "mandate.credential.IntrospectCredential",
        "summary": "IntrospectCredential",
        "tags": [
          "credential"
        ],
        "requestBody": {
          "description": "The input `mandate.credential.IntrospectCredential` declares.",
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/mandate.credential.IntrospectCredential.Input"
              }
            }
          }
        },
        "responses": {
          "202": {
            "description": "Outcome `accepted`: the branch the specification declares for this input. Events this branch emits are published to consumers, not returned here.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/mandate.credential.IntrospectCredential.accepted.Response"
                }
              }
            }
          },
          "502": {
            "description": "Outcome `denied`: something outside the request refused. The input was acceptable, so the caller has nothing to correct and a retry is meaningful.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/mandate.credential.IntrospectCredential.denied.Response"
                }
              }
            }
          }
        }
      }
    },
    "/credential/commands/IssueAuthorizationCode": {
      "post": {
        "operationId": "mandate.credential.IssueAuthorizationCode",
        "summary": "IssueAuthorizationCode",
        "tags": [
          "credential"
        ],
        "requestBody": {
          "description": "The input `mandate.credential.IssueAuthorizationCode` declares.",
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/mandate.credential.IssueAuthorizationCode.Input"
              }
            }
          }
        },
        "responses": {
          "202": {
            "description": "Outcome `accepted`: the branch the specification declares for this input. Events this branch emits are published to consumers, not returned here.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/mandate.credential.IssueAuthorizationCode.accepted.Response"
                }
              }
            }
          },
          "502": {
            "description": "Outcome `denied`: something outside the request refused. The input was acceptable, so the caller has nothing to correct and a retry is meaningful.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/mandate.credential.IssueAuthorizationCode.denied.Response"
                }
              }
            }
          }
        }
      }
    },
    "/credential/commands/IssueReferenceCredential": {
      "post": {
        "operationId": "mandate.credential.IssueReferenceCredential",
        "summary": "IssueReferenceCredential",
        "tags": [
          "credential"
        ],
        "requestBody": {
          "description": "The input `mandate.credential.IssueReferenceCredential` declares.",
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/mandate.credential.IssueReferenceCredential.Input"
              }
            }
          }
        },
        "responses": {
          "202": {
            "description": "Outcome `accepted`: the branch the specification declares for this input. Events this branch emits are published to consumers, not returned here.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/mandate.credential.IssueReferenceCredential.accepted.Response"
                }
              }
            }
          },
          "502": {
            "description": "Outcome `denied`: something outside the request refused. The input was acceptable, so the caller has nothing to correct and a retry is meaningful.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/mandate.credential.IssueReferenceCredential.denied.Response"
                }
              }
            }
          }
        }
      }
    },
    "/credential/commands/IssueSelfContainedCredential": {
      "post": {
        "operationId": "mandate.credential.IssueSelfContainedCredential",
        "summary": "IssueSelfContainedCredential",
        "tags": [
          "credential"
        ],
        "requestBody": {
          "description": "The input `mandate.credential.IssueSelfContainedCredential` declares.",
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/mandate.credential.IssueSelfContainedCredential.Input"
              }
            }
          }
        },
        "responses": {
          "202": {
            "description": "Outcome `accepted`: the branch the specification declares for this input. Events this branch emits are published to consumers, not returned here.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/mandate.credential.IssueSelfContainedCredential.accepted.Response"
                }
              }
            }
          },
          "502": {
            "description": "Outcome `denied`: something outside the request refused. The input was acceptable, so the caller has nothing to correct and a retry is meaningful.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/mandate.credential.IssueSelfContainedCredential.denied.Response"
                }
              }
            }
          }
        }
      }
    },
    "/credential/commands/RedeemAuthorizationCode": {
      "post": {
        "operationId": "mandate.credential.RedeemAuthorizationCode",
        "summary": "RedeemAuthorizationCode",
        "tags": [
          "credential"
        ],
        "requestBody": {
          "description": "The input `mandate.credential.RedeemAuthorizationCode` declares.",
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/mandate.credential.RedeemAuthorizationCode.Input"
              }
            }
          }
        },
        "responses": {
          "202": {
            "description": "Outcome `accepted`: the branch the specification declares for this input. Events this branch emits are published to consumers, not returned here.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/mandate.credential.RedeemAuthorizationCode.accepted.Response"
                }
              }
            }
          },
          "409": {
            "description": "Outcome `wrong-state`: the input was acceptable and the subject is in a state this command does not act from. Resending the same request changes nothing until something else moves it.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/mandate.credential.RedeemAuthorizationCode.wrong-state.Response"
                }
              }
            }
          },
          "502": {
            "description": "Outcome `denied`: something outside the request refused. The input was acceptable, so the caller has nothing to correct and a retry is meaningful.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/mandate.credential.RedeemAuthorizationCode.denied.Response"
                }
              }
            }
          }
        }
      }
    },
    "/credential/commands/RegisterResourceServer": {
      "post": {
        "operationId": "mandate.credential.RegisterResourceServer",
        "summary": "RegisterResourceServer",
        "tags": [
          "credential"
        ],
        "requestBody": {
          "description": "The input `mandate.credential.RegisterResourceServer` declares.",
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/mandate.credential.RegisterResourceServer.Input"
              }
            }
          }
        },
        "responses": {
          "202": {
            "description": "Outcome `accepted`: the branch the specification declares for this input. Events this branch emits are published to consumers, not returned here.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/mandate.credential.RegisterResourceServer.accepted.Response"
                }
              }
            }
          },
          "502": {
            "description": "Outcome `denied`: something outside the request refused. The input was acceptable, so the caller has nothing to correct and a retry is meaningful.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/mandate.credential.RegisterResourceServer.denied.Response"
                }
              }
            }
          }
        }
      }
    },
    "/credential/commands/RegisterSigningKey": {
      "post": {
        "operationId": "mandate.credential.RegisterSigningKey",
        "summary": "RegisterSigningKey",
        "tags": [
          "credential"
        ],
        "requestBody": {
          "description": "The input `mandate.credential.RegisterSigningKey` declares.",
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/mandate.credential.RegisterSigningKey.Input"
              }
            }
          }
        },
        "responses": {
          "202": {
            "description": "Outcome `accepted`: the branch the specification declares for this input. Events this branch emits are published to consumers, not returned here.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/mandate.credential.RegisterSigningKey.accepted.Response"
                }
              }
            }
          },
          "502": {
            "description": "Outcome `denied`: something outside the request refused. The input was acceptable, so the caller has nothing to correct and a retry is meaningful.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/mandate.credential.RegisterSigningKey.denied.Response"
                }
              }
            }
          }
        }
      }
    },
    "/credential/commands/RetireSigningKey": {
      "post": {
        "operationId": "mandate.credential.RetireSigningKey",
        "summary": "RetireSigningKey",
        "tags": [
          "credential"
        ],
        "requestBody": {
          "description": "The input `mandate.credential.RetireSigningKey` declares.",
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/mandate.credential.RetireSigningKey.Input"
              }
            }
          }
        },
        "responses": {
          "202": {
            "description": "Outcome `accepted`: the branch the specification declares for this input. Events this branch emits are published to consumers, not returned here.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/mandate.credential.RetireSigningKey.accepted.Response"
                }
              }
            }
          },
          "409": {
            "description": "Outcome `wrong-state`: the input was acceptable and the subject is in a state this command does not act from. Resending the same request changes nothing until something else moves it.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/mandate.credential.RetireSigningKey.wrong-state.Response"
                }
              }
            }
          },
          "502": {
            "description": "Outcome `denied`: something outside the request refused. The input was acceptable, so the caller has nothing to correct and a retry is meaningful.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/mandate.credential.RetireSigningKey.denied.Response"
                }
              }
            }
          }
        }
      }
    },
    "/credential/commands/RevokeAccessCredential": {
      "post": {
        "operationId": "mandate.credential.RevokeAccessCredential",
        "summary": "RevokeAccessCredential",
        "tags": [
          "credential"
        ],
        "requestBody": {
          "description": "The input `mandate.credential.RevokeAccessCredential` declares.",
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/mandate.credential.RevokeAccessCredential.Input"
              }
            }
          }
        },
        "responses": {
          "202": {
            "description": "Outcome `accepted`: the branch the specification declares for this input. Events this branch emits are published to consumers, not returned here.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/mandate.credential.RevokeAccessCredential.accepted.Response"
                }
              }
            }
          },
          "409": {
            "description": "Outcome `wrong-state`: the input was acceptable and the subject is in a state this command does not act from. Resending the same request changes nothing until something else moves it.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/mandate.credential.RevokeAccessCredential.wrong-state.Response"
                }
              }
            }
          },
          "502": {
            "description": "Outcome `denied`: something outside the request refused. The input was acceptable, so the caller has nothing to correct and a retry is meaningful.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/mandate.credential.RevokeAccessCredential.denied.Response"
                }
              }
            }
          }
        }
      }
    },
    "/credential/commands/RevokeSigningKey": {
      "post": {
        "operationId": "mandate.credential.RevokeSigningKey",
        "summary": "RevokeSigningKey",
        "tags": [
          "credential"
        ],
        "requestBody": {
          "description": "The input `mandate.credential.RevokeSigningKey` declares.",
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/mandate.credential.RevokeSigningKey.Input"
              }
            }
          }
        },
        "responses": {
          "202": {
            "description": "Outcome `accepted`: the branch the specification declares for this input. Events this branch emits are published to consumers, not returned here.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/mandate.credential.RevokeSigningKey.accepted.Response"
                }
              }
            }
          },
          "409": {
            "description": "Outcome `wrong-state`: the input was acceptable and the subject is in a state this command does not act from. Resending the same request changes nothing until something else moves it.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/mandate.credential.RevokeSigningKey.wrong-state.Response"
                }
              }
            }
          },
          "502": {
            "description": "Outcome `denied`: something outside the request refused. The input was acceptable, so the caller has nothing to correct and a retry is meaningful.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/mandate.credential.RevokeSigningKey.denied.Response"
                }
              }
            }
          }
        }
      }
    }
  },
  "components": {
    "schemas": {
      "mandate.core.Action": {
        "title": "Action",
        "x-ess-name": "mandate.core.Action",
        "x-ess-kind": "newtype",
        "type": "string"
      },
      "mandate.core.Audience": {
        "title": "Audience",
        "x-ess-name": "mandate.core.Audience",
        "x-ess-kind": "newtype",
        "type": "string"
      },
      "mandate.core.AuthorityScope": {
        "title": "AuthorityScope",
        "x-ess-name": "mandate.core.AuthorityScope",
        "x-ess-kind": "struct",
        "type": "object",
        "properties": {
          "actions": {
            "type": "array",
            "items": {
              "$ref": "#/components/schemas/mandate.core.Action"
            }
          },
          "resources": {
            "type": "array",
            "items": {
              "$ref": "#/components/schemas/mandate.core.ResourceRef"
            }
          },
          "space": {
            "$ref": "#/components/schemas/mandate.core.SpaceId"
          }
        },
        "required": [
          "actions",
          "resources"
        ],
        "additionalProperties": false
      },
      "mandate.core.AuthorizationCodeId": {
        "title": "AuthorizationCodeId",
        "x-ess-name": "mandate.core.AuthorizationCodeId",
        "x-ess-kind": "newtype",
        "type": "string",
        "format": "uuid",
        "pattern": "^[0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{12}$"
      },
      "mandate.core.CorrelationId": {
        "title": "CorrelationId",
        "x-ess-name": "mandate.core.CorrelationId",
        "x-ess-kind": "newtype",
        "type": "string"
      },
      "mandate.core.CredentialId": {
        "title": "CredentialId",
        "x-ess-name": "mandate.core.CredentialId",
        "x-ess-kind": "newtype",
        "type": "string",
        "format": "uuid",
        "pattern": "^[0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{12}$"
      },
      "mandate.core.CredentialKind": {
        "title": "CredentialKind",
        "x-ess-name": "mandate.core.CredentialKind",
        "x-ess-kind": "enum",
        "type": "string",
        "enum": [
          "SelfContained",
          "Reference"
        ]
      },
      "mandate.core.CredentialProfile": {
        "title": "CredentialProfile",
        "x-ess-name": "mandate.core.CredentialProfile",
        "x-ess-kind": "struct",
        "type": "object",
        "properties": {
          "name": {
            "type": "string"
          },
          "kind": {
            "$ref": "#/components/schemas/mandate.core.CredentialKind"
          },
          "revocation": {
            "$ref": "#/components/schemas/mandate.core.RevocationGuarantee"
          },
          "max_ttl": {
            "type": "string",
            "format": "duration"
          },
          "positive_cache_ttl": {
            "type": "string",
            "format": "duration"
          },
          "requires_online_authorization": {
            "type": "boolean"
          }
        },
        "required": [
          "name",
          "kind",
          "revocation",
          "max_ttl",
          "positive_cache_ttl",
          "requires_online_authorization"
        ],
        "additionalProperties": false
      },
      "mandate.core.CredentialProof": {
        "title": "CredentialProof",
        "x-ess-name": "mandate.core.CredentialProof",
        "x-ess-kind": "newtype",
        "type": "string",
        "pattern": "^(?:[A-Za-z0-9+/]{4})*(?:[A-Za-z0-9+/]{2}==|[A-Za-z0-9+/]{3}=)?$",
        "contentEncoding": "base64"
      },
      "mandate.core.DelegationId": {
        "title": "DelegationId",
        "x-ess-name": "mandate.core.DelegationId",
        "x-ess-kind": "newtype",
        "type": "string",
        "format": "uuid",
        "pattern": "^[0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{12}$"
      },
      "mandate.core.DenialReason": {
        "title": "DenialReason",
        "x-ess-name": "mandate.core.DenialReason",
        "x-ess-kind": "enum",
        "type": "string",
        "enum": [
          "Denied",
          "ApprovalRequired",
          "InvalidCredential",
          "TenantMismatch",
          "AudienceMismatch",
          "Unavailable",
          "StaleEpoch"
        ]
      },
      "mandate.core.ExecutionId": {
        "title": "ExecutionId",
        "x-ess-name": "mandate.core.ExecutionId",
        "x-ess-kind": "newtype",
        "type": "string",
        "format": "uuid",
        "pattern": "^[0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{12}$"
      },
      "mandate.core.KeyReference": {
        "title": "KeyReference",
        "x-ess-name": "mandate.core.KeyReference",
        "x-ess-kind": "newtype",
        "type": "string"
      },
      "mandate.core.OAuthClientId": {
        "title": "OAuthClientId",
        "x-ess-name": "mandate.core.OAuthClientId",
        "x-ess-kind": "newtype",
        "type": "string",
        "format": "uuid",
        "pattern": "^[0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{12}$"
      },
      "mandate.core.OrganizationId": {
        "title": "OrganizationId",
        "x-ess-name": "mandate.core.OrganizationId",
        "x-ess-kind": "newtype",
        "type": "string",
        "format": "uuid",
        "pattern": "^[0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{12}$"
      },
      "mandate.core.PkceChallenge": {
        "title": "PkceChallenge",
        "x-ess-name": "mandate.core.PkceChallenge",
        "x-ess-kind": "newtype",
        "type": "string"
      },
      "mandate.core.PkceMethod": {
        "title": "PkceMethod",
        "x-ess-name": "mandate.core.PkceMethod",
        "x-ess-kind": "enum",
        "type": "string",
        "enum": [
          "S256"
        ]
      },
      "mandate.core.PrincipalId": {
        "title": "PrincipalId",
        "x-ess-name": "mandate.core.PrincipalId",
        "x-ess-kind": "newtype",
        "type": "string",
        "format": "uuid",
        "pattern": "^[0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{12}$"
      },
      "mandate.core.RedirectUri": {
        "title": "RedirectUri",
        "x-ess-name": "mandate.core.RedirectUri",
        "x-ess-kind": "newtype",
        "type": "string"
      },
      "mandate.core.ResourceId": {
        "title": "ResourceId",
        "x-ess-name": "mandate.core.ResourceId",
        "x-ess-kind": "newtype",
        "type": "string",
        "format": "uuid",
        "pattern": "^[0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{12}$"
      },
      "mandate.core.ResourceRef": {
        "title": "ResourceRef",
        "x-ess-name": "mandate.core.ResourceRef",
        "x-ess-kind": "struct",
        "type": "object",
        "properties": {
          "resource_type": {
            "$ref": "#/components/schemas/mandate.core.ResourceType"
          },
          "resource_id": {
            "$ref": "#/components/schemas/mandate.core.ResourceId"
          }
        },
        "required": [
          "resource_type",
          "resource_id"
        ],
        "additionalProperties": false
      },
      "mandate.core.ResourceServerId": {
        "title": "ResourceServerId",
        "x-ess-name": "mandate.core.ResourceServerId",
        "x-ess-kind": "newtype",
        "type": "string",
        "format": "uuid",
        "pattern": "^[0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{12}$"
      },
      "mandate.core.ResourceType": {
        "title": "ResourceType",
        "x-ess-name": "mandate.core.ResourceType",
        "x-ess-kind": "newtype",
        "type": "string"
      },
      "mandate.core.RevocationGuarantee": {
        "title": "RevocationGuarantee",
        "x-ess-name": "mandate.core.RevocationGuarantee",
        "x-ess-kind": "enum",
        "type": "string",
        "enum": [
          "ImmediateOnline",
          "BoundedOffline"
        ]
      },
      "mandate.core.SessionId": {
        "title": "SessionId",
        "x-ess-name": "mandate.core.SessionId",
        "x-ess-kind": "newtype",
        "type": "string",
        "format": "uuid",
        "pattern": "^[0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{12}$"
      },
      "mandate.core.SigningAlgorithm": {
        "title": "SigningAlgorithm",
        "x-ess-name": "mandate.core.SigningAlgorithm",
        "x-ess-kind": "newtype",
        "type": "string"
      },
      "mandate.core.SigningKeyId": {
        "title": "SigningKeyId",
        "x-ess-name": "mandate.core.SigningKeyId",
        "x-ess-kind": "newtype",
        "type": "string",
        "format": "uuid",
        "pattern": "^[0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{12}$"
      },
      "mandate.core.SpaceId": {
        "title": "SpaceId",
        "x-ess-name": "mandate.core.SpaceId",
        "x-ess-kind": "newtype",
        "type": "string",
        "format": "uuid",
        "pattern": "^[0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{12}$"
      },
      "mandate.core.VerifiedContext": {
        "title": "VerifiedContext",
        "x-ess-name": "mandate.core.VerifiedContext",
        "x-ess-kind": "struct",
        "type": "object",
        "properties": {
          "subject": {
            "$ref": "#/components/schemas/mandate.core.PrincipalId"
          },
          "actor": {
            "$ref": "#/components/schemas/mandate.core.PrincipalId"
          },
          "organization": {
            "$ref": "#/components/schemas/mandate.core.OrganizationId"
          },
          "audience": {
            "$ref": "#/components/schemas/mandate.core.Audience"
          },
          "credential": {
            "$ref": "#/components/schemas/mandate.core.CredentialId"
          },
          "delegation": {
            "$ref": "#/components/schemas/mandate.core.DelegationId"
          },
          "execution": {
            "$ref": "#/components/schemas/mandate.core.ExecutionId"
          },
          "correlation": {
            "$ref": "#/components/schemas/mandate.core.CorrelationId"
          }
        },
        "required": [
          "subject",
          "organization",
          "audience",
          "credential",
          "correlation"
        ],
        "additionalProperties": false
      },
      "mandate.credential.Denied.Error": {
        "title": "Denied payload",
        "description": "Fail closed; no credential, authority or lifecycle mutation on refusal.",
        "x-ess-name": "mandate.credential.Denied",
        "x-ess-kind": "error-payload",
        "type": "object",
        "properties": {
          "reason": {
            "$ref": "#/components/schemas/mandate.core.DenialReason"
          }
        },
        "required": [
          "reason"
        ],
        "additionalProperties": false
      },
      "mandate.credential.DisableResourceServer.Input": {
        "title": "DisableResourceServer input",
        "x-ess-name": "mandate.credential.DisableResourceServer",
        "x-ess-kind": "command-input",
        "type": "object",
        "properties": {
          "id": {
            "$ref": "#/components/schemas/mandate.core.ResourceServerId"
          },
          "context": {
            "$ref": "#/components/schemas/mandate.core.VerifiedContext"
          }
        },
        "required": [
          "id",
          "context"
        ],
        "additionalProperties": false
      },
      "mandate.credential.DisableResourceServer.accepted.Response": {
        "additionalProperties": false,
        "description": "Taken when no other outcome's condition matched. A `mandate.credential.ResourceServer` has moved to `Disabled`, along `disable`. The instance is the one `id` names. Emits `ResourceServerDisabled`, published to consumers rather than returned here.",
        "properties": {
          "outcome": {
            "const": "accepted",
            "description": "Which declared outcome the command took."
          }
        },
        "required": [
          "outcome"
        ],
        "type": "object"
      },
      "mandate.credential.DisableResourceServer.denied.Response": {
        "additionalProperties": false,
        "description": "Decided outside the request: Caller lacks resource-server administration authority, server is outside the verified organization, or durable disablement cannot prevent subsequent issuance..",
        "properties": {
          "error": {
            "const": "mandate.credential.Denied",
            "description": "Fail closed; no credential, authority or lifecycle mutation on refusal.",
            "type": "string"
          },
          "outcome": {
            "const": "denied",
            "description": "Which declared outcome the command took."
          },
          "payload": {
            "$ref": "#/components/schemas/mandate.credential.Denied.Error"
          }
        },
        "required": [
          "outcome",
          "error",
          "payload"
        ],
        "type": "object"
      },
      "mandate.credential.DisableResourceServer.wrong-state.Response": {
        "additionalProperties": false,
        "description": "Taken when the subject is in a state none of this command's declared moves start from. Which states those are is the lifecycle's answer, not this command's.",
        "properties": {
          "error": {
            "const": "mandate.credential.Denied",
            "description": "Fail closed; no credential, authority or lifecycle mutation on refusal.",
            "type": "string"
          },
          "outcome": {
            "const": "wrong-state",
            "description": "Which declared outcome the command took."
          },
          "payload": {
            "$ref": "#/components/schemas/mandate.credential.Denied.Error"
          }
        },
        "required": [
          "outcome",
          "error",
          "payload"
        ],
        "type": "object"
      },
      "mandate.credential.ExchangeCredential.Input": {
        "title": "ExchangeCredential input",
        "x-ess-name": "mandate.credential.ExchangeCredential",
        "x-ess-kind": "command-input",
        "type": "object",
        "properties": {
          "subject_proof": {
            "$ref": "#/components/schemas/mandate.core.CredentialProof"
          },
          "actor_proof": {
            "$ref": "#/components/schemas/mandate.core.CredentialProof"
          },
          "target": {
            "$ref": "#/components/schemas/mandate.core.ResourceServerId"
          },
          "requested_scope": {
            "$ref": "#/components/schemas/mandate.core.AuthorityScope"
          },
          "delegation_id": {
            "$ref": "#/components/schemas/mandate.core.DelegationId"
          }
        },
        "required": [
          "subject_proof",
          "target",
          "requested_scope"
        ],
        "additionalProperties": false
      },
      "mandate.credential.ExchangeCredential.accepted.Response": {
        "additionalProperties": false,
        "description": "Taken when no other outcome's condition matched. A `mandate.credential.AccessCredential` now exists, in `Active`. Its identity is published as `credential_id` on `mandate.credential.TokenExchangeAllowed`. Emits `TokenExchangeAllowed`, published to consumers rather than returned here.",
        "properties": {
          "outcome": {
            "const": "accepted",
            "description": "Which declared outcome the command took."
          }
        },
        "required": [
          "outcome"
        ],
        "type": "object"
      },
      "mandate.credential.ExchangeCredential.denied.Response": {
        "additionalProperties": false,
        "description": "Decided outside the request: Either independently validated proof is invalid/revoked/expired/stale; actor, tenant, registered target/source, scope, space, delegation or ceiling binding fails; transitive delegation is requested; approval is required; or authority/expiry narrowing and durable audit fail..",
        "properties": {
          "error": {
            "const": "mandate.credential.Denied",
            "description": "Fail closed; no credential, authority or lifecycle mutation on refusal.",
            "type": "string"
          },
          "outcome": {
            "const": "denied",
            "description": "Which declared outcome the command took."
          },
          "payload": {
            "$ref": "#/components/schemas/mandate.credential.Denied.Error"
          }
        },
        "required": [
          "outcome",
          "error",
          "payload"
        ],
        "type": "object"
      },
      "mandate.credential.IntrospectCredential.Input": {
        "title": "IntrospectCredential input",
        "x-ess-name": "mandate.credential.IntrospectCredential",
        "x-ess-kind": "command-input",
        "type": "object",
        "properties": {
          "caller_proof": {
            "$ref": "#/components/schemas/mandate.core.CredentialProof"
          },
          "credential_proof": {
            "$ref": "#/components/schemas/mandate.core.CredentialProof"
          }
        },
        "required": [
          "caller_proof",
          "credential_proof"
        ],
        "additionalProperties": false
      },
      "mandate.credential.IntrospectCredential.accepted.Response": {
        "additionalProperties": false,
        "description": "An active answer carries the descriptor and the credential_id of the record this log holds. An inactive answer carries neither — that is the answer for a credential this deployment revoked, one whose expiry has passed, and a well-formed proof that resolves to no record at all, which are one answer here and not three. The three are distinguished by nothing this event carries, deliberately, because a caller holding a well-formed proof learns only whether it is usable. This outcome creates, moves and updates nothing, and CredentialIntrospected folds into no record — its credential_id names an instance only when one exists in this log, and a fold reading it must not take the name for the existence of a record some other event created. The presented credential may have been issued by a deployment this log never saw, which is why the field is optional rather than the event's subject. Taken when no other outcome's condition matched. Emits `CredentialIntrospected`, published to consumers rather than returned here.",
        "properties": {
          "outcome": {
            "const": "accepted",
            "description": "Which declared outcome the command took."
          }
        },
        "required": [
          "outcome"
        ],
        "type": "object"
      },
      "mandate.credential.IntrospectCredential.denied.Response": {
        "additionalProperties": false,
        "description": "Decided outside the request: Caller proof lacks introspection authority for the registered server/tenant or is itself invalid, revoked or expired, the presented credential proof is malformed, principal/connection/epoch validation fails, audience mismatches, or authoritative online resolution is unavailable..",
        "properties": {
          "error": {
            "const": "mandate.credential.Denied",
            "description": "Fail closed; no credential, authority or lifecycle mutation on refusal.",
            "type": "string"
          },
          "outcome": {
            "const": "denied",
            "description": "Which declared outcome the command took."
          },
          "payload": {
            "$ref": "#/components/schemas/mandate.credential.Denied.Error"
          }
        },
        "required": [
          "outcome",
          "error",
          "payload"
        ],
        "type": "object"
      },
      "mandate.credential.IssueAuthorizationCode.Input": {
        "title": "IssueAuthorizationCode input",
        "x-ess-name": "mandate.credential.IssueAuthorizationCode",
        "x-ess-kind": "command-input",
        "type": "object",
        "properties": {
          "context": {
            "$ref": "#/components/schemas/mandate.core.VerifiedContext"
          },
          "client_id": {
            "$ref": "#/components/schemas/mandate.core.OAuthClientId"
          },
          "session_id": {
            "$ref": "#/components/schemas/mandate.core.SessionId"
          },
          "target": {
            "$ref": "#/components/schemas/mandate.core.ResourceServerId"
          },
          "requested_scope": {
            "$ref": "#/components/schemas/mandate.core.AuthorityScope"
          },
          "challenge": {
            "$ref": "#/components/schemas/mandate.core.PkceChallenge"
          },
          "method": {
            "$ref": "#/components/schemas/mandate.core.PkceMethod"
          },
          "redirect_uri": {
            "$ref": "#/components/schemas/mandate.core.RedirectUri"
          },
          "expires_at": {
            "type": "string",
            "format": "date-time"
          }
        },
        "required": [
          "context",
          "client_id",
          "session_id",
          "target",
          "requested_scope",
          "challenge",
          "method",
          "redirect_uri",
          "expires_at"
        ],
        "additionalProperties": false
      },
      "mandate.credential.IssueAuthorizationCode.accepted.Response": {
        "additionalProperties": false,
        "description": "STS stores only a non-reversible verifier bound to the validated client, session, exact redirect, S256 challenge, registered target, narrowed scope and bounded expiry. Only the transient code is returned to the public-client adapter. Taken when no other outcome's condition matched. A `mandate.credential.AuthorizationCode` now exists, in `Issued`. Its identity is published as `code_id` on `mandate.credential.AuthorizationCodeIssued`. Emits `AuthorizationCodeIssued`, published to consumers rather than returned here.",
        "properties": {
          "outcome": {
            "const": "accepted",
            "description": "Which declared outcome the command took."
          }
        },
        "required": [
          "outcome"
        ],
        "type": "object"
      },
      "mandate.credential.IssueAuthorizationCode.denied.Response": {
        "additionalProperties": false,
        "description": "Decided outside the request: Trusted control-plane caller/session context, registered public client, exact redirect URI, S256 policy, tenant/target agreement, authority narrowing or bounded expiry validation fails, or the client the code would be bound to is disabled..",
        "properties": {
          "error": {
            "const": "mandate.credential.Denied",
            "description": "Fail closed; no credential, authority or lifecycle mutation on refusal.",
            "type": "string"
          },
          "outcome": {
            "const": "denied",
            "description": "Which declared outcome the command took."
          },
          "payload": {
            "$ref": "#/components/schemas/mandate.credential.Denied.Error"
          }
        },
        "required": [
          "outcome",
          "error",
          "payload"
        ],
        "type": "object"
      },
      "mandate.credential.IssueReferenceCredential.Input": {
        "title": "IssueReferenceCredential input",
        "x-ess-name": "mandate.credential.IssueReferenceCredential",
        "x-ess-kind": "command-input",
        "type": "object",
        "properties": {
          "context": {
            "$ref": "#/components/schemas/mandate.core.VerifiedContext"
          },
          "target": {
            "$ref": "#/components/schemas/mandate.core.ResourceServerId"
          },
          "requested_scope": {
            "$ref": "#/components/schemas/mandate.core.AuthorityScope"
          }
        },
        "required": [
          "context",
          "target",
          "requested_scope"
        ],
        "additionalProperties": false
      },
      "mandate.credential.IssueReferenceCredential.accepted.Response": {
        "additionalProperties": false,
        "description": "Taken when no other outcome's condition matched. A `mandate.credential.AccessCredential` now exists, in `Active`. Its identity is published as `credential_id` on `mandate.credential.CredentialReferenceIssued`. Emits `CredentialReferenceIssued`, published to consumers rather than returned here.",
        "properties": {
          "outcome": {
            "const": "accepted",
            "description": "Which declared outcome the command took."
          }
        },
        "required": [
          "outcome"
        ],
        "type": "object"
      },
      "mandate.credential.IssueReferenceCredential.denied.Response": {
        "additionalProperties": false,
        "description": "Decided outside the request: Validated context is expired/revoked/stale, subject/actor authority or ceilings do not cover requested scope, target/profile is unregistered/disabled/outside tenant, expiry cannot be bounded, or verifier-only persistence and required audit cannot commit..",
        "properties": {
          "error": {
            "const": "mandate.credential.Denied",
            "description": "Fail closed; no credential, authority or lifecycle mutation on refusal.",
            "type": "string"
          },
          "outcome": {
            "const": "denied",
            "description": "Which declared outcome the command took."
          },
          "payload": {
            "$ref": "#/components/schemas/mandate.credential.Denied.Error"
          }
        },
        "required": [
          "outcome",
          "error",
          "payload"
        ],
        "type": "object"
      },
      "mandate.credential.IssueSelfContainedCredential.Input": {
        "title": "IssueSelfContainedCredential input",
        "x-ess-name": "mandate.credential.IssueSelfContainedCredential",
        "x-ess-kind": "command-input",
        "type": "object",
        "properties": {
          "context": {
            "$ref": "#/components/schemas/mandate.core.VerifiedContext"
          },
          "target": {
            "$ref": "#/components/schemas/mandate.core.ResourceServerId"
          },
          "requested_scope": {
            "$ref": "#/components/schemas/mandate.core.AuthorityScope"
          }
        },
        "required": [
          "context",
          "target",
          "requested_scope"
        ],
        "additionalProperties": false
      },
      "mandate.credential.IssueSelfContainedCredential.accepted.Response": {
        "additionalProperties": false,
        "description": "Taken when no other outcome's condition matched. A `mandate.credential.AccessCredential` now exists, in `Active`. Its identity is published as `credential_id` on `mandate.credential.CredentialSelfContainedIssued`. Emits `CredentialSelfContainedIssued`, published to consumers rather than returned here.",
        "properties": {
          "outcome": {
            "const": "accepted",
            "description": "Which declared outcome the command took."
          }
        },
        "required": [
          "outcome"
        ],
        "type": "object"
      },
      "mandate.credential.IssueSelfContainedCredential.denied.Response": {
        "additionalProperties": false,
        "description": "Decided outside the request: Validated context is expired/revoked/stale, subject/actor authority or ceilings do not cover requested scope, target/profile/signing algorithm or key is unadmitted, expiry cannot be bounded, or the promised revocation/audit guarantee cannot be met..",
        "properties": {
          "error": {
            "const": "mandate.credential.Denied",
            "description": "Fail closed; no credential, authority or lifecycle mutation on refusal.",
            "type": "string"
          },
          "outcome": {
            "const": "denied",
            "description": "Which declared outcome the command took."
          },
          "payload": {
            "$ref": "#/components/schemas/mandate.credential.Denied.Error"
          }
        },
        "required": [
          "outcome",
          "error",
          "payload"
        ],
        "type": "object"
      },
      "mandate.credential.RedeemAuthorizationCode.Input": {
        "title": "RedeemAuthorizationCode input",
        "x-ess-name": "mandate.credential.RedeemAuthorizationCode",
        "x-ess-kind": "command-input",
        "type": "object",
        "properties": {
          "code_id": {
            "$ref": "#/components/schemas/mandate.core.AuthorizationCodeId"
          },
          "client_id": {
            "$ref": "#/components/schemas/mandate.core.OAuthClientId"
          },
          "code": {
            "$ref": "#/components/schemas/mandate.core.CredentialProof"
          },
          "pkce_verifier": {
            "$ref": "#/components/schemas/mandate.core.CredentialProof"
          },
          "redirect_uri": {
            "$ref": "#/components/schemas/mandate.core.RedirectUri"
          }
        },
        "required": [
          "code_id",
          "client_id",
          "code",
          "pkce_verifier",
          "redirect_uri"
        ],
        "additionalProperties": false
      },
      "mandate.credential.RedeemAuthorizationCode.accepted.Response": {
        "additionalProperties": false,
        "description": "STS atomically consumes the code and persists the narrowed credential and audit outbox. The returned credential remains bound to the code target, scope, session and expiry; a failed or replayed transaction produces no credential. The command takes no context input and admits no caller-supplied selector — the generated context on the emitted event takes its subject, organization and audience from the code record and the session it names through the STS's session port, its credential as the credential_id this outcome issues, its correlation as the one the outcome mints for this request, and its actor, delegation and execution as absent unless the code record names them. The audience is the one published by the registration the code record's target names. The epoch whose staleness the denial names is the session's own, resolved through that same port, because a redemption presents no source credential of its own. The credential this outcome issues is recorded by mandate.credential.AuthorizationCodeRedeemed, which carries the whole mandate.credential.AccessCredential record, and the epoch snapshot it binds is the one this command answers in its response; the outcome's one subject stays the code it consumes, so the seeding is declared in this domain's header. Taken when no other outcome's condition matched. A `mandate.credential.AuthorizationCode` has moved to `Consumed`, along `consume`. The instance is the one `code_id` names. Emits `AuthorizationCodeRedeemed`, published to consumers rather than returned here.",
        "properties": {
          "outcome": {
            "const": "accepted",
            "description": "Which declared outcome the command took."
          }
        },
        "required": [
          "outcome"
        ],
        "type": "object"
      },
      "mandate.credential.RedeemAuthorizationCode.denied.Response": {
        "additionalProperties": false,
        "description": "Decided outside the request: Code proof does not match the server-resolved code_id; code is expired; client, redirect URI or S256 verifier mismatches; the bound client is disabled; source/session epoch is stale; registered target is disabled or outside the verified tenant; or narrowing/atomic issuance validation fails..",
        "properties": {
          "error": {
            "const": "mandate.credential.Denied",
            "description": "Fail closed; no credential, authority or lifecycle mutation on refusal.",
            "type": "string"
          },
          "outcome": {
            "const": "denied",
            "description": "Which declared outcome the command took."
          },
          "payload": {
            "$ref": "#/components/schemas/mandate.credential.Denied.Error"
          }
        },
        "required": [
          "outcome",
          "error",
          "payload"
        ],
        "type": "object"
      },
      "mandate.credential.RedeemAuthorizationCode.wrong-state.Response": {
        "additionalProperties": false,
        "description": "Taken when the subject is in a state none of this command's declared moves start from. Which states those are is the lifecycle's answer, not this command's.",
        "properties": {
          "error": {
            "const": "mandate.credential.Denied",
            "description": "Fail closed; no credential, authority or lifecycle mutation on refusal.",
            "type": "string"
          },
          "outcome": {
            "const": "wrong-state",
            "description": "Which declared outcome the command took."
          },
          "payload": {
            "$ref": "#/components/schemas/mandate.credential.Denied.Error"
          }
        },
        "required": [
          "outcome",
          "error",
          "payload"
        ],
        "type": "object"
      },
      "mandate.credential.RegisterResourceServer.Input": {
        "title": "RegisterResourceServer input",
        "x-ess-name": "mandate.credential.RegisterResourceServer",
        "x-ess-kind": "command-input",
        "type": "object",
        "properties": {
          "context": {
            "$ref": "#/components/schemas/mandate.core.VerifiedContext"
          },
          "audience": {
            "$ref": "#/components/schemas/mandate.core.Audience"
          },
          "profile": {
            "$ref": "#/components/schemas/mandate.core.CredentialProfile"
          },
          "allowed_exchange_sources": {
            "type": "array",
            "items": {
              "$ref": "#/components/schemas/mandate.core.ResourceServerId"
            }
          }
        },
        "required": [
          "context",
          "audience",
          "profile",
          "allowed_exchange_sources"
        ],
        "additionalProperties": false
      },
      "mandate.credential.RegisterResourceServer.accepted.Response": {
        "additionalProperties": false,
        "description": "Taken when no other outcome's condition matched. A `mandate.credential.ResourceServer` now exists, in `Enabled`. Its identity is published as `id` on `mandate.credential.ResourceServerRegistered`. Emits `ResourceServerRegistered`, published to consumers rather than returned here.",
        "properties": {
          "outcome": {
            "const": "accepted",
            "description": "Which declared outcome the command took."
          }
        },
        "required": [
          "outcome"
        ],
        "type": "object"
      },
      "mandate.credential.RegisterResourceServer.denied.Response": {
        "additionalProperties": false,
        "description": "Decided outside the request: Caller lacks resource-server administration authority, audience registration is ambiguous, profile semantics are unadmitted, or an allowed source server is unresolved/disabled/outside the verified organization..",
        "properties": {
          "error": {
            "const": "mandate.credential.Denied",
            "description": "Fail closed; no credential, authority or lifecycle mutation on refusal.",
            "type": "string"
          },
          "outcome": {
            "const": "denied",
            "description": "Which declared outcome the command took."
          },
          "payload": {
            "$ref": "#/components/schemas/mandate.credential.Denied.Error"
          }
        },
        "required": [
          "outcome",
          "error",
          "payload"
        ],
        "type": "object"
      },
      "mandate.credential.RegisterSigningKey.Input": {
        "title": "RegisterSigningKey input",
        "x-ess-name": "mandate.credential.RegisterSigningKey",
        "x-ess-kind": "command-input",
        "type": "object",
        "properties": {
          "context": {
            "$ref": "#/components/schemas/mandate.core.VerifiedContext"
          },
          "key_reference": {
            "$ref": "#/components/schemas/mandate.core.KeyReference"
          },
          "algorithm": {
            "$ref": "#/components/schemas/mandate.core.SigningAlgorithm"
          },
          "not_before": {
            "type": "string",
            "format": "date-time"
          },
          "expires_at": {
            "type": "string",
            "format": "date-time"
          }
        },
        "required": [
          "context",
          "key_reference",
          "algorithm",
          "not_before",
          "expires_at"
        ],
        "additionalProperties": false
      },
      "mandate.credential.RegisterSigningKey.accepted.Response": {
        "additionalProperties": false,
        "description": "The key enters the contract Recorded, which is what rotation requires — RetireSigningKey denies a retirement with no overlapping replacement published for continued verification, and no replacement can exist until a key can be registered. SigningKeyRegistered carries the whole mandate.credential.SigningKey record — the key identity, the reference the deployment resolves to the material, the thumbprint of the public key, the algorithm name and the validity window — so the credential fold materializes the key from this event alone and reads no command input or response. The mandate.core.SigningKeyId is the kid the signer publishes and a credential names; the thumbprint is the RFC 7638 JWK thumbprint of the public key this outcome resolved from key_reference, so a revocation record naming a kid and a thumbprint is rebuilt from this log without resolving the material of a key that was revoked as compromised. Both are decided by this outcome and read from its response. No key material enters the contract — KeyReference is a handle to material the deployment holds, and no event here carries a secret. The algorithm is a name and not an admitted algorithm (UNMAPPED-ALGORITHM-POLICY); the deployment's verifier-side allowlist admits it or the registration is denied. A key reference, or the key material it resolves to, already held by a recorded key is refused in every state that key can be in, including Retired and Revoked, so material the deployment revoked never returns under a second identity. The window ordering is the entity's invariant, checked by the deciding handler; the synthesized accepted scenario builds an equal window and is expected to fail until ESS's synthesizer consults entity invariants (routed to the ESS wave). No command replaces a key in place; rotation registers the successor and retires the predecessor. Taken when no other outcome's condition matched. A `mandate.credential.SigningKey` now exists, in `Recorded`. Its identity is published as `id` on `mandate.credential.SigningKeyRegistered`. Emits `SigningKeyRegistered`, published to consumers rather than returned here.",
        "properties": {
          "outcome": {
            "const": "accepted",
            "description": "Which declared outcome the command took."
          }
        },
        "required": [
          "outcome"
        ],
        "type": "object"
      },
      "mandate.credential.RegisterSigningKey.denied.Response": {
        "additionalProperties": false,
        "description": "Decided outside the request: Caller lacks platform signing-key administration authority, the algorithm is outside the deployment's admitted set, the key reference is unresolvable, or the key reference or the key material is already recorded..",
        "properties": {
          "error": {
            "const": "mandate.credential.Denied",
            "description": "Fail closed; no credential, authority or lifecycle mutation on refusal.",
            "type": "string"
          },
          "outcome": {
            "const": "denied",
            "description": "Which declared outcome the command took."
          },
          "payload": {
            "$ref": "#/components/schemas/mandate.credential.Denied.Error"
          }
        },
        "required": [
          "outcome",
          "error",
          "payload"
        ],
        "type": "object"
      },
      "mandate.credential.RetireSigningKey.Input": {
        "title": "RetireSigningKey input",
        "x-ess-name": "mandate.credential.RetireSigningKey",
        "x-ess-kind": "command-input",
        "type": "object",
        "properties": {
          "id": {
            "$ref": "#/components/schemas/mandate.core.SigningKeyId"
          },
          "context": {
            "$ref": "#/components/schemas/mandate.core.VerifiedContext"
          }
        },
        "required": [
          "id",
          "context"
        ],
        "additionalProperties": false
      },
      "mandate.credential.RetireSigningKey.accepted.Response": {
        "additionalProperties": false,
        "description": "Rotation, not revocation. A retired key signs nothing further; it remains admitted for verifying credentials already issued under it until they expire, which is the overlapping rotation period the key requirements demand. Taken when no other outcome's condition matched. A `mandate.credential.SigningKey` has moved to `Retired`, along `retire`. The instance is the one `id` names. Emits `SigningKeyRetired`, published to consumers rather than returned here.",
        "properties": {
          "outcome": {
            "const": "accepted",
            "description": "Which declared outcome the command took."
          }
        },
        "required": [
          "outcome"
        ],
        "type": "object"
      },
      "mandate.credential.RetireSigningKey.denied.Response": {
        "additionalProperties": false,
        "description": "Decided outside the request: Caller lacks platform signing-key administration authority, the key is unresolved, no overlapping replacement key is published for continued verification, or retirement cannot durably stop further issuance under the key..",
        "properties": {
          "error": {
            "const": "mandate.credential.Denied",
            "description": "Fail closed; no credential, authority or lifecycle mutation on refusal.",
            "type": "string"
          },
          "outcome": {
            "const": "denied",
            "description": "Which declared outcome the command took."
          },
          "payload": {
            "$ref": "#/components/schemas/mandate.credential.Denied.Error"
          }
        },
        "required": [
          "outcome",
          "error",
          "payload"
        ],
        "type": "object"
      },
      "mandate.credential.RetireSigningKey.wrong-state.Response": {
        "additionalProperties": false,
        "description": "Taken when the subject is in a state none of this command's declared moves start from. Which states those are is the lifecycle's answer, not this command's.",
        "properties": {
          "error": {
            "const": "mandate.credential.Denied",
            "description": "Fail closed; no credential, authority or lifecycle mutation on refusal.",
            "type": "string"
          },
          "outcome": {
            "const": "wrong-state",
            "description": "Which declared outcome the command took."
          },
          "payload": {
            "$ref": "#/components/schemas/mandate.credential.Denied.Error"
          }
        },
        "required": [
          "outcome",
          "error",
          "payload"
        ],
        "type": "object"
      },
      "mandate.credential.RevokeAccessCredential.Input": {
        "title": "RevokeAccessCredential input",
        "x-ess-name": "mandate.credential.RevokeAccessCredential",
        "x-ess-kind": "command-input",
        "type": "object",
        "properties": {
          "id": {
            "$ref": "#/components/schemas/mandate.core.CredentialId"
          },
          "context": {
            "$ref": "#/components/schemas/mandate.core.VerifiedContext"
          }
        },
        "required": [
          "id",
          "context"
        ],
        "additionalProperties": false
      },
      "mandate.credential.RevokeAccessCredential.accepted.Response": {
        "additionalProperties": false,
        "description": "Taken when no other outcome's condition matched. A `mandate.credential.AccessCredential` has moved to `Revoked`, along `revoke`. The instance is the one `id` names. Emits `AccessCredentialRevoked`, published to consumers rather than returned here.",
        "properties": {
          "outcome": {
            "const": "accepted",
            "description": "Which declared outcome the command took."
          }
        },
        "required": [
          "outcome"
        ],
        "type": "object"
      },
      "mandate.credential.RevokeAccessCredential.denied.Response": {
        "additionalProperties": false,
        "description": "Decided outside the request: Caller lacks credential-revocation authority, resolved credential is outside the verified organization, or the named profile revocation guarantee cannot be met..",
        "properties": {
          "error": {
            "const": "mandate.credential.Denied",
            "description": "Fail closed; no credential, authority or lifecycle mutation on refusal.",
            "type": "string"
          },
          "outcome": {
            "const": "denied",
            "description": "Which declared outcome the command took."
          },
          "payload": {
            "$ref": "#/components/schemas/mandate.credential.Denied.Error"
          }
        },
        "required": [
          "outcome",
          "error",
          "payload"
        ],
        "type": "object"
      },
      "mandate.credential.RevokeAccessCredential.wrong-state.Response": {
        "additionalProperties": false,
        "description": "Taken when the subject is in a state none of this command's declared moves start from. Which states those are is the lifecycle's answer, not this command's.",
        "properties": {
          "error": {
            "const": "mandate.credential.Denied",
            "description": "Fail closed; no credential, authority or lifecycle mutation on refusal.",
            "type": "string"
          },
          "outcome": {
            "const": "wrong-state",
            "description": "Which declared outcome the command took."
          },
          "payload": {
            "$ref": "#/components/schemas/mandate.credential.Denied.Error"
          }
        },
        "required": [
          "outcome",
          "error",
          "payload"
        ],
        "type": "object"
      },
      "mandate.credential.RevokeSigningKey.Input": {
        "title": "RevokeSigningKey input",
        "x-ess-name": "mandate.credential.RevokeSigningKey",
        "x-ess-kind": "command-input",
        "type": "object",
        "properties": {
          "id": {
            "$ref": "#/components/schemas/mandate.core.SigningKeyId"
          },
          "context": {
            "$ref": "#/components/schemas/mandate.core.VerifiedContext"
          }
        },
        "required": [
          "id",
          "context"
        ],
        "additionalProperties": false
      },
      "mandate.credential.RevokeSigningKey.accepted.Response": {
        "additionalProperties": false,
        "description": "The emergency procedure. A revoked key is admitted for neither issuance nor verification, and the self-contained credentials it signed are refused from that point; the key record itself is kept. Taken when no other outcome's condition matched. A `mandate.credential.SigningKey` has moved to `Revoked`, along `revoke`. The instance is the one `id` names. Emits `SigningKeyRevoked`, published to consumers rather than returned here.",
        "properties": {
          "outcome": {
            "const": "accepted",
            "description": "Which declared outcome the command took."
          }
        },
        "required": [
          "outcome"
        ],
        "type": "object"
      },
      "mandate.credential.RevokeSigningKey.denied.Response": {
        "additionalProperties": false,
        "description": "Decided outside the request: Caller lacks platform signing-key administration authority, the key is unresolved, or emergency revocation cannot durably stop both issuance and verification under the key and refuse the credentials it signed..",
        "properties": {
          "error": {
            "const": "mandate.credential.Denied",
            "description": "Fail closed; no credential, authority or lifecycle mutation on refusal.",
            "type": "string"
          },
          "outcome": {
            "const": "denied",
            "description": "Which declared outcome the command took."
          },
          "payload": {
            "$ref": "#/components/schemas/mandate.credential.Denied.Error"
          }
        },
        "required": [
          "outcome",
          "error",
          "payload"
        ],
        "type": "object"
      },
      "mandate.credential.RevokeSigningKey.wrong-state.Response": {
        "additionalProperties": false,
        "description": "Taken when the subject is in a state none of this command's declared moves start from. Which states those are is the lifecycle's answer, not this command's.",
        "properties": {
          "error": {
            "const": "mandate.credential.Denied",
            "description": "Fail closed; no credential, authority or lifecycle mutation on refusal.",
            "type": "string"
          },
          "outcome": {
            "const": "wrong-state",
            "description": "Which declared outcome the command took."
          },
          "payload": {
            "$ref": "#/components/schemas/mandate.credential.Denied.Error"
          }
        },
        "required": [
          "outcome",
          "error",
          "payload"
        ],
        "type": "object"
      }
    }
  },
  "x-ess-entities": {
    "mandate.core.Action": {
      "title": "Action",
      "x-ess-name": "mandate.core.Action",
      "x-ess-kind": "newtype",
      "type": "string"
    },
    "mandate.core.Audience": {
      "title": "Audience",
      "x-ess-name": "mandate.core.Audience",
      "x-ess-kind": "newtype",
      "type": "string"
    },
    "mandate.core.AuthorityScope": {
      "title": "AuthorityScope",
      "x-ess-name": "mandate.core.AuthorityScope",
      "x-ess-kind": "struct",
      "type": "object",
      "properties": {
        "actions": {
          "type": "array",
          "items": {
            "$ref": "#/x-ess-entities/mandate.core.Action"
          }
        },
        "resources": {
          "type": "array",
          "items": {
            "$ref": "#/x-ess-entities/mandate.core.ResourceRef"
          }
        },
        "space": {
          "$ref": "#/x-ess-entities/mandate.core.SpaceId"
        }
      },
      "required": [
        "actions",
        "resources"
      ],
      "additionalProperties": false
    },
    "mandate.core.AuthorizationCodeId": {
      "title": "AuthorizationCodeId",
      "x-ess-name": "mandate.core.AuthorizationCodeId",
      "x-ess-kind": "newtype",
      "type": "string",
      "format": "uuid",
      "pattern": "^[0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{12}$"
    },
    "mandate.core.CredentialDescriptor": {
      "title": "CredentialDescriptor",
      "x-ess-name": "mandate.core.CredentialDescriptor",
      "x-ess-kind": "struct",
      "type": "object",
      "properties": {
        "kind": {
          "$ref": "#/x-ess-entities/mandate.core.CredentialKind"
        },
        "subject": {
          "$ref": "#/x-ess-entities/mandate.core.PrincipalId"
        },
        "actor": {
          "$ref": "#/x-ess-entities/mandate.core.PrincipalId"
        },
        "organization": {
          "$ref": "#/x-ess-entities/mandate.core.OrganizationId"
        },
        "audience": {
          "$ref": "#/x-ess-entities/mandate.core.Audience"
        },
        "scope": {
          "$ref": "#/x-ess-entities/mandate.core.AuthorityScope"
        },
        "delegation": {
          "$ref": "#/x-ess-entities/mandate.core.DelegationId"
        },
        "execution": {
          "$ref": "#/x-ess-entities/mandate.core.ExecutionId"
        },
        "expires_at": {
          "type": "string",
          "format": "date-time"
        }
      },
      "required": [
        "kind",
        "subject",
        "organization",
        "audience",
        "scope",
        "expires_at"
      ],
      "additionalProperties": false
    },
    "mandate.core.CredentialId": {
      "title": "CredentialId",
      "x-ess-name": "mandate.core.CredentialId",
      "x-ess-kind": "newtype",
      "type": "string",
      "format": "uuid",
      "pattern": "^[0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{12}$"
    },
    "mandate.core.CredentialKind": {
      "title": "CredentialKind",
      "x-ess-name": "mandate.core.CredentialKind",
      "x-ess-kind": "enum",
      "type": "string",
      "enum": [
        "SelfContained",
        "Reference"
      ]
    },
    "mandate.core.CredentialProfile": {
      "title": "CredentialProfile",
      "x-ess-name": "mandate.core.CredentialProfile",
      "x-ess-kind": "struct",
      "type": "object",
      "properties": {
        "name": {
          "type": "string"
        },
        "kind": {
          "$ref": "#/x-ess-entities/mandate.core.CredentialKind"
        },
        "revocation": {
          "$ref": "#/x-ess-entities/mandate.core.RevocationGuarantee"
        },
        "max_ttl": {
          "type": "string",
          "format": "duration"
        },
        "positive_cache_ttl": {
          "type": "string",
          "format": "duration"
        },
        "requires_online_authorization": {
          "type": "boolean"
        }
      },
      "required": [
        "name",
        "kind",
        "revocation",
        "max_ttl",
        "positive_cache_ttl",
        "requires_online_authorization"
      ],
      "additionalProperties": false
    },
    "mandate.core.CredentialVerifier": {
      "title": "CredentialVerifier",
      "x-ess-name": "mandate.core.CredentialVerifier",
      "x-ess-kind": "newtype",
      "type": "string"
    },
    "mandate.core.DelegationId": {
      "title": "DelegationId",
      "x-ess-name": "mandate.core.DelegationId",
      "x-ess-kind": "newtype",
      "type": "string",
      "format": "uuid",
      "pattern": "^[0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{12}$"
    },
    "mandate.core.EpochSnapshotRef": {
      "title": "EpochSnapshotRef",
      "x-ess-name": "mandate.core.EpochSnapshotRef",
      "x-ess-kind": "newtype",
      "type": "string",
      "format": "uuid",
      "pattern": "^[0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{12}$"
    },
    "mandate.core.ExecutionId": {
      "title": "ExecutionId",
      "x-ess-name": "mandate.core.ExecutionId",
      "x-ess-kind": "newtype",
      "type": "string",
      "format": "uuid",
      "pattern": "^[0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{12}$"
    },
    "mandate.core.KeyReference": {
      "title": "KeyReference",
      "x-ess-name": "mandate.core.KeyReference",
      "x-ess-kind": "newtype",
      "type": "string"
    },
    "mandate.core.OAuthClientId": {
      "title": "OAuthClientId",
      "x-ess-name": "mandate.core.OAuthClientId",
      "x-ess-kind": "newtype",
      "type": "string",
      "format": "uuid",
      "pattern": "^[0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{12}$"
    },
    "mandate.core.OrganizationId": {
      "title": "OrganizationId",
      "x-ess-name": "mandate.core.OrganizationId",
      "x-ess-kind": "newtype",
      "type": "string",
      "format": "uuid",
      "pattern": "^[0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{12}$"
    },
    "mandate.core.PkceChallenge": {
      "title": "PkceChallenge",
      "x-ess-name": "mandate.core.PkceChallenge",
      "x-ess-kind": "newtype",
      "type": "string"
    },
    "mandate.core.PkceMethod": {
      "title": "PkceMethod",
      "x-ess-name": "mandate.core.PkceMethod",
      "x-ess-kind": "enum",
      "type": "string",
      "enum": [
        "S256"
      ]
    },
    "mandate.core.PrincipalId": {
      "title": "PrincipalId",
      "x-ess-name": "mandate.core.PrincipalId",
      "x-ess-kind": "newtype",
      "type": "string",
      "format": "uuid",
      "pattern": "^[0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{12}$"
    },
    "mandate.core.RedirectUri": {
      "title": "RedirectUri",
      "x-ess-name": "mandate.core.RedirectUri",
      "x-ess-kind": "newtype",
      "type": "string"
    },
    "mandate.core.ResourceId": {
      "title": "ResourceId",
      "x-ess-name": "mandate.core.ResourceId",
      "x-ess-kind": "newtype",
      "type": "string",
      "format": "uuid",
      "pattern": "^[0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{12}$"
    },
    "mandate.core.ResourceRef": {
      "title": "ResourceRef",
      "x-ess-name": "mandate.core.ResourceRef",
      "x-ess-kind": "struct",
      "type": "object",
      "properties": {
        "resource_type": {
          "$ref": "#/x-ess-entities/mandate.core.ResourceType"
        },
        "resource_id": {
          "$ref": "#/x-ess-entities/mandate.core.ResourceId"
        }
      },
      "required": [
        "resource_type",
        "resource_id"
      ],
      "additionalProperties": false
    },
    "mandate.core.ResourceServerId": {
      "title": "ResourceServerId",
      "x-ess-name": "mandate.core.ResourceServerId",
      "x-ess-kind": "newtype",
      "type": "string",
      "format": "uuid",
      "pattern": "^[0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{12}$"
    },
    "mandate.core.ResourceType": {
      "title": "ResourceType",
      "x-ess-name": "mandate.core.ResourceType",
      "x-ess-kind": "newtype",
      "type": "string"
    },
    "mandate.core.RevocationGuarantee": {
      "title": "RevocationGuarantee",
      "x-ess-name": "mandate.core.RevocationGuarantee",
      "x-ess-kind": "enum",
      "type": "string",
      "enum": [
        "ImmediateOnline",
        "BoundedOffline"
      ]
    },
    "mandate.core.SessionId": {
      "title": "SessionId",
      "x-ess-name": "mandate.core.SessionId",
      "x-ess-kind": "newtype",
      "type": "string",
      "format": "uuid",
      "pattern": "^[0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{12}$"
    },
    "mandate.core.SigningAlgorithm": {
      "title": "SigningAlgorithm",
      "x-ess-name": "mandate.core.SigningAlgorithm",
      "x-ess-kind": "newtype",
      "type": "string"
    },
    "mandate.core.SigningKeyId": {
      "title": "SigningKeyId",
      "x-ess-name": "mandate.core.SigningKeyId",
      "x-ess-kind": "newtype",
      "type": "string",
      "format": "uuid",
      "pattern": "^[0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{12}$"
    },
    "mandate.core.SpaceId": {
      "title": "SpaceId",
      "x-ess-name": "mandate.core.SpaceId",
      "x-ess-kind": "newtype",
      "type": "string",
      "format": "uuid",
      "pattern": "^[0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{12}$"
    },
    "mandate.credential.AccessCredential": {
      "title": "AccessCredential",
      "x-ess-name": "mandate.credential.AccessCredential",
      "x-ess-kind": "entity",
      "type": "object",
      "properties": {
        "id": {
          "$ref": "#/x-ess-entities/mandate.core.CredentialId"
        },
        "descriptor": {
          "$ref": "#/x-ess-entities/mandate.core.CredentialDescriptor"
        },
        "reference_verifier": {
          "$ref": "#/x-ess-entities/mandate.core.CredentialVerifier"
        },
        "epochs": {
          "$ref": "#/x-ess-entities/mandate.core.EpochSnapshotRef",
          "x-ess-relation": {
            "name": "epoch_snapshot_record",
            "kind": "references",
            "source": "mandate.credential.AccessCredential",
            "target": "mandate.identity.SecurityEpochSnapshot",
            "cardinality": "one",
            "via": "epochs",
            "$ref": "#/x-ess-entities/mandate.identity.SecurityEpochSnapshot"
          }
        },
        "issued_at": {
          "type": "string",
          "format": "date-time"
        },
        "state": {
          "$ref": "#/x-ess-entities/mandate.credential.AccessCredential.State"
        }
      },
      "required": [
        "id",
        "descriptor",
        "issued_at",
        "state"
      ],
      "additionalProperties": false
    },
    "mandate.credential.AccessCredential.State": {
      "title": "State",
      "x-ess-name": "mandate.credential.AccessCredential.State",
      "x-ess-kind": "enum",
      "type": "string",
      "enum": [
        "Active",
        "Revoked"
      ]
    },
    "mandate.credential.AuthorizationCode": {
      "title": "AuthorizationCode",
      "x-ess-name": "mandate.credential.AuthorizationCode",
      "x-ess-kind": "entity",
      "type": "object",
      "properties": {
        "id": {
          "$ref": "#/x-ess-entities/mandate.core.AuthorizationCodeId"
        },
        "client_id": {
          "$ref": "#/x-ess-entities/mandate.core.OAuthClientId",
          "x-ess-relation": {
            "name": "client_id_record",
            "kind": "references",
            "source": "mandate.credential.AuthorizationCode",
            "target": "mandate.federation.OAuthClient",
            "cardinality": "one",
            "via": "client_id",
            "$ref": "#/x-ess-entities/mandate.federation.OAuthClient"
          }
        },
        "session_id": {
          "$ref": "#/x-ess-entities/mandate.core.SessionId",
          "x-ess-relation": {
            "name": "session_id_record",
            "kind": "references",
            "source": "mandate.credential.AuthorizationCode",
            "target": "mandate.identity.Session",
            "cardinality": "one",
            "via": "session_id",
            "$ref": "#/x-ess-entities/mandate.identity.Session"
          }
        },
        "verifier": {
          "$ref": "#/x-ess-entities/mandate.core.CredentialVerifier"
        },
        "challenge": {
          "$ref": "#/x-ess-entities/mandate.core.PkceChallenge"
        },
        "method": {
          "$ref": "#/x-ess-entities/mandate.core.PkceMethod"
        },
        "redirect_uri": {
          "$ref": "#/x-ess-entities/mandate.core.RedirectUri"
        },
        "expires_at": {
          "type": "string",
          "format": "date-time"
        },
        "target": {
          "$ref": "#/x-ess-entities/mandate.core.ResourceServerId",
          "x-ess-relation": {
            "name": "target_record",
            "kind": "references",
            "source": "mandate.credential.AuthorizationCode",
            "target": "mandate.credential.ResourceServer",
            "cardinality": "one",
            "via": "target",
            "$ref": "#/x-ess-entities/mandate.credential.ResourceServer"
          }
        },
        "scope": {
          "$ref": "#/x-ess-entities/mandate.core.AuthorityScope"
        },
        "state": {
          "$ref": "#/x-ess-entities/mandate.credential.AuthorizationCode.State"
        }
      },
      "required": [
        "id",
        "client_id",
        "session_id",
        "verifier",
        "challenge",
        "method",
        "redirect_uri",
        "expires_at",
        "target",
        "scope",
        "state"
      ],
      "additionalProperties": false
    },
    "mandate.credential.AuthorizationCode.State": {
      "title": "State",
      "x-ess-name": "mandate.credential.AuthorizationCode.State",
      "x-ess-kind": "enum",
      "type": "string",
      "enum": [
        "Consumed",
        "Issued"
      ]
    },
    "mandate.credential.ResourceServer": {
      "title": "ResourceServer",
      "x-ess-name": "mandate.credential.ResourceServer",
      "x-ess-kind": "entity",
      "type": "object",
      "properties": {
        "id": {
          "$ref": "#/x-ess-entities/mandate.core.ResourceServerId"
        },
        "organization_id": {
          "$ref": "#/x-ess-entities/mandate.core.OrganizationId",
          "x-ess-relation": {
            "name": "organization_id_record",
            "kind": "references",
            "source": "mandate.credential.ResourceServer",
            "target": "mandate.tenancy.Organization",
            "cardinality": "one",
            "via": "organization_id",
            "$ref": "#/x-ess-entities/mandate.tenancy.Organization"
          }
        },
        "audience": {
          "$ref": "#/x-ess-entities/mandate.core.Audience"
        },
        "credential_profile": {
          "$ref": "#/x-ess-entities/mandate.core.CredentialProfile"
        },
        "allowed_exchange_sources": {
          "type": "array",
          "items": {
            "$ref": "#/x-ess-entities/mandate.core.ResourceServerId"
          },
          "x-ess-relation": {
            "name": "allowed_exchange_source_records",
            "kind": "references",
            "source": "mandate.credential.ResourceServer",
            "target": "mandate.credential.ResourceServer",
            "cardinality": "many",
            "via": "allowed_exchange_sources",
            "$ref": "#/x-ess-entities/mandate.credential.ResourceServer"
          }
        },
        "state": {
          "$ref": "#/x-ess-entities/mandate.credential.ResourceServer.State"
        }
      },
      "required": [
        "id",
        "organization_id",
        "audience",
        "credential_profile",
        "allowed_exchange_sources",
        "state"
      ],
      "additionalProperties": false
    },
    "mandate.credential.ResourceServer.State": {
      "title": "State",
      "x-ess-name": "mandate.credential.ResourceServer.State",
      "x-ess-kind": "enum",
      "type": "string",
      "enum": [
        "Disabled",
        "Enabled"
      ]
    },
    "mandate.credential.SigningKey": {
      "title": "SigningKey",
      "x-ess-name": "mandate.credential.SigningKey",
      "x-ess-kind": "entity",
      "type": "object",
      "properties": {
        "id": {
          "$ref": "#/x-ess-entities/mandate.core.SigningKeyId"
        },
        "key_reference": {
          "$ref": "#/x-ess-entities/mandate.core.KeyReference"
        },
        "thumbprint": {
          "type": "string"
        },
        "algorithm": {
          "$ref": "#/x-ess-entities/mandate.core.SigningAlgorithm"
        },
        "not_before": {
          "type": "string",
          "format": "date-time"
        },
        "expires_at": {
          "type": "string",
          "format": "date-time"
        },
        "state": {
          "$ref": "#/x-ess-entities/mandate.credential.SigningKey.State"
        }
      },
      "required": [
        "id",
        "key_reference",
        "thumbprint",
        "algorithm",
        "not_before",
        "expires_at",
        "state"
      ],
      "additionalProperties": false
    },
    "mandate.credential.SigningKey.State": {
      "title": "State",
      "x-ess-name": "mandate.credential.SigningKey.State",
      "x-ess-kind": "enum",
      "type": "string",
      "enum": [
        "Recorded",
        "Retired",
        "Revoked"
      ]
    }
  }
}
