Revocation
The signed statement that cuts a grant, valid from the grant's issuer, its delegate key, or an admin over its subject, and evaluated late so nothing is deleted.
Fetching schema…

Part of Stem. This page defines the Revocation blob.

A Revocation names one Grant and, when its signer is allowed to cut that grant, removes the grant from the live graph.

Fields

The schema extends blob.

field

type

required

meaning

type

literal Revocation

yes

Blob type tag.

grant

CID

yes

The Grant being revoked.

reason

string, at most 512 characters

no

A public note.

Rules

A revocation is valid when its signer is the grant's issuer (retraction), the key the grant was issued to (renunciation), or a principal with admin over the grant's subject (admin revocation). Admins keep their revocation power over their admin reach even after their own path is cut; that is the Keyline rule that makes admin rotation possible. Revocations are applied in the live pass of evaluation after the positive pass has computed admin reach, so their effect is independent of arrival order. A revoked grant's dependent grants stop being live unless another path supports them. Nothing is deleted: the revoked grant stays indexed and auditable, and blobs that were written under it stay stored but are no longer applied as current state, so a mistaken revocation can be undone by a new grant without data loss. Revocation does not unshare bytes; see disclosure.

Today (HM24)

Reserved and unbuilt: a commented-out RevokeCapability RPC. Capabilities last for ever.

Example

{ "type": "Revocation", "signer": {"/": {"bytes": "7QEE...Starlight"}}, "sig": {"/": {"bytes": "..."}}, "ts": 1760515200000, "grant": {"/": "bafyreigrantcollaboratorread0000000000000000000000000000000"}, "reason": "Review finished" }

Do you like what you are reading? Subscribe to receive updates.

Unsubscribe anytime