Reference · Specification

The protocol,
specified.

Six normative documents describe the contract. Schemas and test vectors make it executable.

Draft-01.1Wire version 1.0RFC 2119 languageCC BY-SA 4.0
The repository is the normative source

This page is a reading guide. The documents on the main branch of arsialabs/arsia-protocol (opens in a new tab) are the source of truth for Draft-01.1.

One foundation. Five primitives.

Core defines the envelope and the trust model. The five primitives, whose initials spell ARSIA, build on it.

How to read it

Begin with Core for the envelope, signing and the trust model. Then read the primitives your application needs: Actions for oversight, State for audit and erasure, Identity for onboarding and keys.

Requirements use RFC 2119 keywords. MUST and MUST NOT are absolute; SHOULD allows exceptions you can justify; MAY is optional.

Three version identifiers mean different things: the specification draft (Draft-01.1), the wire version carried in v (1.0), and the SDK release (1.0.1). See versions.

Message intents

IntentPurpose
requestAsk another agent to perform an action, with capabilities, payload and compliance requirements.
responseReturn the result, correlated to the request.
eventA one-way notification. No response expected.
errorA structured error with a standard code and description.
pending_approvalPause and ask a human reviewer before executing.
approval_decisionThe reviewer’s decision, approved or denied, with a justification.

Rollback is not a separate intent: it is a request whose payload type is the original action followed by /rollback.

Error codes

Fourteen standard codes, each with an HTTP status and a retry policy, so a failure means the same thing to every implementation.

  • invalid_request
  • unauthorized
  • forbidden
  • not_found
  • conflict
  • payload_too_large
  • rate_limited
  • internal_error
  • not_implemented
  • service_unavailable
  • certificate_invalid
  • certificate_expired
  • key_mismatch
  • certificate_revoked

Machine-readable artifacts

Every structure has a JSON Schema (Draft 2020-12), and the test vectors exercise valid and invalid messages with real cryptography.

ArtifactDraft-01.1
JSON Schemas31 schemas, JSON Schema 2020-12
Test vectors611 vectors: 413 valid, 123 invalid, 75 runtime-only
Test keypairs57 published: 53 Ed25519, 2 ES256, 2 RS256
Compliance profiles7 profiles in one JSON file
LicenseApache 2.0 for schemas, profiles and test vectors

Follow changes

Pin your implementation to a reviewed revision, and check the changelog before updating.

Esc