DatasetMetadata

Canonical JSON document anchored on-chain by DatasetVersionRegistry.

A document of this kind carries a schema field matching xny://schemas/dataset-metadata/<major>.<minor> — the version is part of the URI, and it is the only place a document's version is recorded.

Canonical JSON document anchored on-chain by DatasetVersionRegistry. Supersedes DatasetMetadata.schema.json (which is now deprecated). Describes the dataset version's storage coordinates, CF list, and encryption metadata. The contributions field has been removed; CF attribution is now derived from the cfListUri merkle tree.

Fields

FieldTypeRequiredDescription
schemastringyesPer-kind versioned schema identifier. Format: xny://schemas/dataset-metadata/<major.minor>. This is the single source of truth for document version; do not use schema_version.
kindstringyesDocument kind discriminator. Always 'dataset-metadata' for this schema.
publisherstringyesDID of the entity that published this document. Pseudonymous identifier written to the permanent Arweave layer. DID-to-identity mapping exists only in an off-chain deletable layer (GDPR note: deletion right does not cover this field).
published_atstringyesRFC 3339 / ISO 8601 UTC timestamp of document publication.
tagsobjectyesFree-form key-value metadata tags for indexing and filtering. Bounded to 32 entries with keys up to 64 characters — conservative structural limits to keep the anchored document small, not a semantic constraint on tag content. Values are permanently written to Arweave alongside the rest of this document: do not put personal data in a tag (see CONVENTIONS.md's GDPR Note).
datasetIdstringyesDataset version identifier. On-chain bytes32 = keccak256(abi.encodePacked(assemblerDidId, manifestId, versionNumber)). 0x-prefixed bytes32 hex: the executor's injectDatasetFields always writes common.Hash.Hex() into this field, and the indexer's decodeBytes32 already requires exactly this shape when reading it back.
versionNumberintegeryesContract-assigned dataset version (1-based) — the third input to datasetId = keccak256(abi.encodePacked(assemblerDidId, manifestId, versionNumber)). The indexer cross-checks it against the on-chain DatasetVersionRegistry anchor. Because it is a JSON integer read by arbitrary (often IEEE-754-backed) parsers, the executor refuses to serialize a version above 2^53-1 (the max safe JSON integer) rather than emit one that would round; on-chain versions are sequential, so this bound is unreachable in practice.
primaryFrontierIdstringyesClaimed primary frontier for this dataset version. Verification input ONLY — not to be trusted directly; authoritative result comes from the derivation chain (cf → task → campaign → frontier).
cfListUristringyesURI pointing to the ordered list of ContributionFingerprint identifiers included in this dataset version (e.g. arweave://...).
cfListHashstringyesIntegrity anchor for the document at cfListUri: sha256 of its raw bytes, bare hex without 0x prefix. Mirrors the manifestUri/manifestHash pairing rather than contributorsMerkleRoot's 0x-keccak256 on-chain convention, because cfListUri (like manifestUri) is a plain off-chain document reference with no on-chain register of its own -- see CONVENTIONS.md's metadataHash Semantics section for the two off-chain-vs-on-chain hash conventions this repo uses. Required for every new dataset publication.
contributorsMerkleRootstringyesRoot of the two-layer Ownership Merkle Tree built over the CF list at cfListUri (see docs/contracts/ownership-merkle-tree.md): Layer-1 is a per-contributor tree over raw cfIds (cfMerkleRoot); Layer-2 has one leaf per contributor DID. This is the SAME value anchored on-chain in DatasetVersionRegistry.contributorsMerkleRoot and verified by OwnershipRegistry.claimDatasetShares; the metadata carries it for offline self-contained verification. 0x-prefixed bytes32 keccak256 hex — unlike the bare-hex sha256 manifestHash, this field mirrors an on-chain bytes32, so it keeps the 0x prefix for direct comparison against the on-chain root.
cfCountintegeryesNumber of ContributionFingerprints in the CF list.
cfListFormatstringyesSerialisation format of the CF list document (e.g. 'ndjson', 'csv'). Consumers use this to select the correct parser.
manifestUristringyesInner-layer encrypted chunk manifest URI — points at the payload listing encrypted under the dataset-version DEK. This field does not define key custody or authorised key release. Distinct from the CF list (cfListUri). Retained from DatasetMetadata for read-path compatibility.
manifestHashstringyesHash of the encrypted chunk manifest bytes referenced by manifestUri. SHA-256 hex digest without a 0x prefix. Inner-layer integrity anchor.
encryptionSuitestringyesSymmetric encryption algorithm used for the inner-layer payload (e.g. 'AES-256-GCM').
statusACTIVE | REVOKED | ARCHIVEDyesDEPRECATED: this value records publication-time intent ONLY and can NEVER transition afterward -- the document is hash-anchored (metadataHash = keccak256(exact bytes), no in-place editing) and DatasetVersionRegistry exposes no metadata-update entry point (only assembleDataset + getters). Consumers MUST NOT render this field as the dataset version's current lifecycle state. Scheduled for removal at the next major bump; see CONVENTIONS.md's Dataset lifecycle ownership matrix for which registry actually owns each real lifecycle transition (stop-sale, grant revocation, content takedown, quality supersession).

Example

{
  "schema": "xny://schemas/dataset-metadata/1.0",
  "kind": "dataset-metadata",
  "publisher": "did:xny:0xabcdef1234567890abcdef1234567890abcdef12",
  "published_at": "2026-06-09T08:15:00Z",
  "tags": { "env": "production" },
  "datasetId": "0x3c4d5e6f7a8b9c0d1e2f3a4b5c6d7e8f9a0b1c2d3e4f5a6b7c8d9e0f1a2b3c4d",
  "versionNumber": 1,
  "primaryFrontierId": "f-life-sciences-2026",
  "cfListUri": "arweave://Vk3aQv6oMx3o1jcN8b5x2eR0p9Tn4cM2sQrL7yX1zHk",
  "cfListHash": "869aa1ec147889482367d6015118e5ce1386ae9a7b821f730eae3ba7a5055b18",
  "contributorsMerkleRoot": "0xd7ee1f75fd0115260d1836cbd4ab58c01383a1673713a69910effe44e8d069c7",
  "cfCount": 142,
  "cfListFormat": "ndjson",
  "manifestUri": "arweave://Ab3cDe4fGh5iJk6lMn7oPq8rSt9uVw0xYz1AB2CD3EF",
  "manifestHash": "9f86d081884c7d659a2feaa0c55ad015a3bf4f1b2b0b822cd15d6c15b0f00a08",
  "encryptionSuite": "AES-256-GCM",
  "status": "ACTIVE"
}

5 rejection cases are kept alongside the schema in docs/schemas/examples/, exercised by validate_schemas.py.

Last updated

On this page