{"lexicon":1,"id":"money.atmosphere.payment.recurringReceipt","defs":{"main":{"type":"record","key":"tid","description":"An immutable SETTLEMENT-EVIDENCE record for the initial settled payment that begins a payer-confirmed recurring relationship, plus the cadence snapshot accepted at enrollment. Explicitly NOT current subscription state: automatic renewals, later tier or cadence changes, merely scheduling a future change, no-charge changes, cancellation, delinquency, and pauses neither create nor update this record. A separately confirmed immediate adjustment that settles money uses money.atmosphere.payment.receipt for that exact settlement; it does not rewrite this record or pretend to encode the new recurring price. The payer action is not by itself publication consent: any new receipt still requires that exact settlement's frozen publication choice and repository authority. A later cancellation followed by a genuinely new enrollment may create a new recurringReceipt for that new relationship's initial settlement. A separate record type is required because Lexicon has no conditional requiredness: the cadence snapshot is required here and absent from money.atmosphere.payment.receipt. Commitment, author-provenance, proof, and policy-dependent lifecycle semantics are identical to money.atmosphere.payment.receipt.","record":{"type":"object","required":["recipients","value","settlement","settledAt","nonce","interval","intervalCount","proofs"],"properties":{"recipients":{"type":"array","minLength":1,"maxLength":32,"items":{"type":"ref","ref":"money.atmosphere.payment.defs#recipientScope"},"description":"Authoritative recipient scopes for this single settled obligation, with optional historical purchase contexts. The money-atmosphere-v1 profile admits exactly one recipient scope; multiple scopes require a separately reviewed supported profile. The complete array is committed. It does not allocate the settlement total or grant access. The retired purchases field is not an alias."},"value":{"type":"union","refs":["money.atmosphere.payment.defs#fiatMinor","money.atmosphere.payment.defs#assetAtomic"],"description":"The single authoritative value satisfied by the initial settlement that begins this recurring relationship, after applicable discounts and charged tax. It is NOT a promise of the future recurring price. Uses the exact shared fiat-minor or asset-atomic variants defined by money.atmosphere.payment.defs; money-atmosphere-v1 treats every unknown tag as record-invalid. Later adjustments and automatic renewal values are not represented here."},"settlement":{"type":"union","refs":["money.atmosphere.payment.defs#attestedSettlement"],"description":"Committed open settlement union. This profile admits only #attestedSettlement with its exact authority DID and visible-ASCII transactionId; flat transactionId/transactionIdAuthority fields, mixed branches and unknown branches are record-invalid. The attested branch requires at least one proof, including the producer's matching-authority proof. Future chain and Zone branches require separate reviewed semantics; no reserved name grants verification or execution authority."},"settledAt":{"type":"string","format":"datetime","description":"UTC instant at which the canonical accepted-settlement authority asserts the recurring relationship's initial settlement occurred (millisecond precision, Z suffix). Not the quote, confirmation, checkout-creation, or record-publication time."},"nonce":{"type":"string","minLength":32,"maxLength":32,"description":"Exactly 32 lowercase hexadecimal characters (implementations MUST enforce ^[0-9a-f]{32}$) encoding 128 bits that MUST be generated by a cryptographically secure random generator, once per payment, never derived from other fields, never reused. See money.atmosphere.payment.receipt."},"interval":{"type":"string","minLength":1,"maxLength":16,"knownValues":["day","week","month","year"],"description":"Billing interval unit accepted when the recurring relationship's initial settlement occurred (cadence snapshot)."},"intervalCount":{"type":"integer","minimum":1,"maximum":366,"description":"Multiplier applied to `interval` (e.g. interval=month, intervalCount=3 bills quarterly). The 366 ceiling admits an annual daily cadence including leap years while rejecting implausibly large immutable billing snapshots; ATM's operational subscription-change quote uses a broader 1095 limit because it is an app-private, expiring workflow object rather than this permanent public receipt. Required and always explicit — writers MUST NOT rely on validator-inserted defaults, so one set of terms has exactly one canonical byte form. Terms snapshot only."},"proofs":{"type":"array","maxLength":10,"items":{"type":"ref","ref":"com.atproto.repo.strongRef"},"description":"References to immutable money.atmosphere.payment.proof records in each attester's own repository. Each URI authority identifies its attester; each cid is the exact canonical AT repository-record CID. The array is required and fixed at creation. Its schema permits zero entries to reserve later profiles, but the broker-attested profile and every ATM-written receipt require at least one proof. Brokered proofs are written first. proofs is the only field removed from the commitment preimage; settlement remains committed. Receipts are immutable. The optional recipient acknowledgment is independently discovered at the full commitment-CID key specified by COMMITMENT_PROFILE.md; it may be published later and never edits this array. Every reference whose URI authority is committed settlement.authority must have a canonical 13-character TID key or the whole receipt is record-invalid. Only that committed broker role supplies lifecycle candidates; unrelated non-broker references are raw observations.","minLength":0}}}}}}