{
  "$schema": "https://json-schema.org/draft/2020-12/schema",
  "$id": "https://real-life.org/trust-tasks/membership-invite/0.2",
  "title": "Payload: membership-invite/0.2 (rltp-membership@0.16, target Trust Tasks framework 0.4)",
  "description": "Payload schema per Trust Tasks 6.3 ($id = Type URI, describes only the payload). The invitation is a conformant DTG InvitationCredential (DTGWG Core Credentials WD01): issuer = the inviting member's anchor (MUST equal the document issuer), credentialSubject.id = the invitee's member anchor (MUST equal the document recipient; signed in so consent cannot be transplanted — accept.subject MUST equal it), group/genesisDigest/card are WD01-legal additional subject properties, validUntil bounds the invite's answerable life and the inviter's reply-key retention, taskContext = the membership thread (MUST equal the document threadId). The credential's DataIntegrityProof is the one authenticity carrier: the enclosing document carries NO document-level proof (Membership Tasks 3.1, 2).",
  "type": "object",
  "required": [
    "invite"
  ],
  "additionalProperties": false,
  "properties": {
    "invite": {
      "type": "object",
      "required": [
        "@context",
        "type",
        "issuer",
        "credentialSubject",
        "validFrom",
        "validUntil",
        "taskContext",
        "proof"
      ],
      "additionalProperties": false,
      "properties": {
        "@context": {
          "type": "array",
          "minItems": 3,
          "maxItems": 3,
          "prefixItems": [
            {
              "const": "https://www.w3.org/ns/credentials/v2"
            },
            {
              "const": "https://firstperson.network/credentials/dtg/v1"
            },
            {
              "const": "https://real-life.org/rltp/v1"
            }
          ],
          "items": false
        },
        "type": {
          "type": "array",
          "minItems": 4,
          "maxItems": 4,
          "allOf": [
            {
              "contains": {
                "const": "VerifiableCredential"
              }
            },
            {
              "contains": {
                "const": "DTGCredential"
              }
            },
            {
              "contains": {
                "const": "InvitationCredential"
              }
            },
            {
              "contains": {
                "const": "MembershipInvite"
              }
            }
          ]
        },
        "issuer": {
          "$ref": "#/$defs/didKey"
        },
        "credentialSubject": {
          "type": "object",
          "required": [
            "id",
            "group",
            "genesisDigest",
            "card"
          ],
          "additionalProperties": false,
          "properties": {
            "id": {
              "$ref": "#/$defs/didKey"
            },
            "group": {
              "$ref": "#/$defs/didKey"
            },
            "genesisDigest": {
              "$ref": "#/$defs/multibaseMultihash"
            },
            "card": {
              "$ref": "https://real-life.org/rltp/v1/schemas/contact-card.schema.json",
              "description": "the inviter's contact card (displayed form): carries the key-agreement key the accept will be sealed to"
            },
            "name": {
              "type": "string",
              "maxLength": 200
            },
            "note": {
              "type": "string",
              "maxLength": 2000
            }
          }
        },
        "validFrom": {
          "$ref": "#/$defs/rfc3339utc"
        },
        "validUntil": {
          "$ref": "#/$defs/rfc3339utc"
        },
        "taskContext": {
          "$ref": "#/$defs/uuid"
        },
        "proof": {
          "type": "object",
          "additionalProperties": false,
          "required": [
            "type",
            "cryptosuite",
            "created",
            "verificationMethod",
            "proofPurpose",
            "proofValue",
            "@context"
          ],
          "properties": {
            "type": {
              "const": "DataIntegrityProof"
            },
            "cryptosuite": {
              "const": "eddsa-jcs-2022"
            },
            "created": {
              "$ref": "#/$defs/rfc3339utc"
            },
            "verificationMethod": {
              "type": "string",
              "pattern": "^did:key:z6Mk[1-9A-HJ-NP-Za-km-z]{44}#z6Mk[1-9A-HJ-NP-Za-km-z]{44}$"
            },
            "proofPurpose": {
              "const": "assertionMethod"
            },
            "proofValue": {
              "type": "string",
              "minLength": 65,
              "maxLength": 89,
              "pattern": "^z[1-9A-HJ-NP-Za-km-z]+$",
              "description": "multibase base58btc of an Ed25519 signature (exactly 64 bytes): 'z' plus 64 to 88 base58 characters — the Encounter 2.3 form, shared verbatim by all three RLTP credential schemas."
            },
            "@context": {
              "type": "array",
              "minItems": 3,
              "maxItems": 3,
              "prefixItems": [
                {
                  "const": "https://www.w3.org/ns/credentials/v2"
                },
                {
                  "const": "https://firstperson.network/credentials/dtg/v1"
                },
                {
                  "const": "https://real-life.org/rltp/v1"
                }
              ],
              "items": false
            }
          }
        }
      }
    }
  },
  "$defs": {
    "didKey": {
      "type": "string",
      "pattern": "^did:key:z6Mk[1-9A-HJ-NP-Za-km-z]{44}$"
    },
    "multibaseMultihash": {
      "type": "string",
      "pattern": "^(u[A-Za-z0-9_-]{45}[AQgw]|z[1-9A-HJ-NP-Za-km-z]{44,48})$",
      "description": "multibase(multihash sha2-256) per Encounter 2.3: emit u, accept u/z"
    },
    "rfc3339utc": {
      "type": "string",
      "maxLength": 24,
      "pattern": "^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9](\\.[0-9]{1,3})?Z$",
      "description": "RFC3339 UTC 'Z', at most 3 fractional-second digits, 24 characters maximum — the Encounter 2.3 securing profile's timestamp language, shared verbatim by all three RLTP credential schemas: a syntactic gate, calendar validity is a parse-time check."
    },
    "uuid": {
      "type": "string",
      "pattern": "^[0-9a-f]{8}-[0-9a-f]{4}-4[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$"
    }
  }
}
