{
  "$schema": "https://json-schema.org/draft/2020-12/schema",
  "$id": "https://karmadue.expo.app/schema/karmadue.v0.json",
  "title": "karmadue.json v0: publisher manifest",
  "description": "Publisher-declared facts about an agent, repo, service or model. Put it at the repository root (karmadue.json) or at https://<domain>/.well-known/karmadue.json. Declarations only: no scores, ratings or verdicts. KarmaDue links the subject to its signed passport; it never writes into this file. Spec: https://karmadue.expo.app/docs/karmadue-json.md",
  "type": "object",
  "additionalProperties": false,
  "required": ["karmadue", "subject", "publisher"],
  "properties": {
    "$schema": { "const": "https://karmadue.expo.app/schema/karmadue.v0.json" },
    "karmadue": { "const": "0", "description": "Spec version." },
    "subject": {
      "type": "object",
      "additionalProperties": false,
      "required": ["type", "name"],
      "properties": {
        "type": { "enum": ["agent", "repo", "service", "model"] },
        "name": { "type": "string", "minLength": 1, "maxLength": 200 },
        "version": { "type": "string", "minLength": 1, "maxLength": 100 },
        "repository": { "type": "string", "pattern": "^https://", "maxLength": 300 },
        "homepage": { "type": "string", "pattern": "^https://", "maxLength": 300 }
      }
    },
    "publisher": {
      "type": "object",
      "additionalProperties": false,
      "required": ["name"],
      "properties": {
        "name": { "type": "string", "minLength": 1, "maxLength": 200 },
        "domain": { "type": "string", "description": "Bare domain the publisher controls, e.g. example.com. Checked by DNS TXT _karmadue.<domain> or its .well-known/karmadue.json.", "pattern": "^(?!-)[A-Za-z0-9-]{1,63}(\\.[A-Za-z0-9-]{1,63})+$", "maxLength": 253 },
        "securityContact": { "type": "string", "description": "Where security reports go: an https security page or /.well-known/security.txt. Not an email address.", "pattern": "^https://[^@\\s]+$", "maxLength": 300 }
      }
    },
    "capabilities": {
      "type": "object",
      "additionalProperties": false,
      "properties": {
        "tools": {
          "type": "array", "maxItems": 500,
          "items": {
            "oneOf": [
              { "type": "string", "minLength": 1, "maxLength": 200 },
              { "type": "object", "additionalProperties": false, "required": ["name"], "properties": { "name": { "type": "string", "minLength": 1, "maxLength": 200 }, "description": { "type": "string", "maxLength": 1000 } } }
            ]
          }
        },
        "permissions": { "type": "array", "maxItems": 100, "items": { "type": "string", "minLength": 1, "maxLength": 200 }, "description": "What it can touch, e.g. read:repo, write:issues, send:email." },
        "network": { "type": "object", "additionalProperties": false, "required": ["access"], "properties": { "access": { "enum": ["none", "allowlist", "any"] }, "domains": { "type": "array", "maxItems": 200, "items": { "type": "string", "maxLength": 200 } } } },
        "filesystem": { "type": "object", "additionalProperties": false, "required": ["access"], "properties": { "access": { "enum": ["none", "read", "read-write"] }, "paths": { "type": "array", "maxItems": 200, "items": { "type": "string", "maxLength": 200 } } } },
        "payments": { "type": "object", "additionalProperties": false, "required": ["access"], "properties": { "access": { "enum": ["none", "request", "autonomous"] }, "maxUsdPerDay": { "type": "number", "minimum": 0 } } },
        "autonomyLevel": { "enum": ["L0", "L1", "L2", "L3", "L4"], "description": "L0 suggests only; L1 acts with approval for each action; L2 acts alone on reversible steps; L3 acts alone within declared permissions; L4 fully autonomous including payments. See https://karmadue.expo.app/standards#autonomy" },
        "humanApprovalRequiredFor": { "type": "array", "maxItems": 100, "items": { "type": "string", "minLength": 1, "maxLength": 200 } }
      }
    },
    "policies": {
      "type": "object",
      "additionalProperties": false,
      "properties": {
        "security": { "type": "string", "pattern": "^https://", "maxLength": 300 },
        "privacy": { "type": "string", "pattern": "^https://", "maxLength": 300 },
        "retention": { "type": "string", "minLength": 1, "maxLength": 300, "description": "How long user data is kept, in words or a URL." },
        "trainsOnUserData": { "type": "boolean" }
      }
    },
    "passport": { "type": "string", "pattern": "^https://karmadue\\.expo\\.app/passport/", "description": "Optional link to the subject's signed KarmaDue passport." }
  }
}
