# WebCode session handles
`SessionScope` owns one in-memory identity boundary. `open(authority, document, source)` creates an opaque `OpenedLibrary`; `validate` requires the same scope, selected authority, exact versionless document, and exact source identity. `replacement` validates first and replaces only complete Documentation or Code bytes without normalization. `refresh` binds a newly authoritative document/source to the same scope.
`OpenedSource` is either `Published(SemVer)` or `Unpublished { id, revision }`. The unpublished ID is stable across overwrites while the revision changes on every accepted KTO transaction. `OpenedLibrary::version_text` returns the model-facing SemVer or unpublished ID. Handles are process-local and confer no authority.
The package performs no I/O, authorization, KTO work, checking, publication, persistence, retry, or locking. Work is linear in copied or validated authored bytes.