Skip to main content

Module contract

Module contract 

Source
Expand description

Frozen Thread-oriented contract; endpoint support is negotiated.

Modules§

analysis_event
Nested message and enum types in AnalysisEvent.
analysis_finding
Nested message and enum types in AnalysisFinding.
annotation_property_predicate
Nested message and enum types in AnnotationPropertyPredicate.
annotation_tag
Nested message and enum types in AnnotationTag.
annotation_tag_predicate
Nested message and enum types in AnnotationTagPredicate.
annotation_value
Nested message and enum types in AnnotationValue.
artifact_event
Nested message and enum types in ArtifactEvent.
attention_event
Nested message and enum types in AttentionEvent.
attention_item
Nested message and enum types in AttentionItem.
begin_pairing_request
Nested message and enum types in BeginPairingRequest.
begin_registration_request
Nested message and enum types in BeginRegistrationRequest.
behavior_assignment
Nested message and enum types in BehaviorAssignment.
behavior_branch
Nested message and enum types in BehaviorBranch.
billing_event
Nested message and enum types in BillingEvent.
blob_read
Nested message and enum types in BlobRead.
bookmark_ref
Nested message and enum types in BookmarkRef.
catalog_event
Nested message and enum types in CatalogEvent.
check_evidence_summary
Nested message and enum types in CheckEvidenceSummary.
checkout_event
Nested message and enum types in CheckoutEvent.
collaboration_anchor
Nested message and enum types in CollaborationAnchor.
collaboration_event
Nested message and enum types in CollaborationEvent.
complete_authentication_request
Nested message and enum types in CompleteAuthenticationRequest.
complete_pairing_request
Nested message and enum types in CompletePairingRequest.
complete_registration_request
Nested message and enum types in CompleteRegistrationRequest.
content_event
Nested message and enum types in ContentEvent.
content_read
Nested message and enum types in ContentRead.
content_tree_entry
Nested message and enum types in ContentTreeEntry.
control_run_request
Nested message and enum types in ControlRunRequest.
create_spool_request
Nested message and enum types in CreateSpoolRequest.
credential_result
Nested message and enum types in CredentialResult.
delegation_record
Nested message and enum types in DelegationRecord.
discussion_record
Nested message and enum types in DiscussionRecord.
entity_ref
Nested message and enum types in EntityRef.
fetch_client_frame
Nested message and enum types in FetchClientFrame.
fetch_open
Nested message and enum types in FetchOpen.
fetch_server_frame
Nested message and enum types in FetchServerFrame.
handle_resolution
Nested message and enum types in HandleResolution.
identity_event
Nested message and enum types in IdentityEvent.
integration_event
Nested message and enum types in IntegrationEvent.
invitation_resolution
Nested message and enum types in InvitationResolution.
material_retention
Nested message and enum types in MaterialRetention.
mutation_receipt
Nested message and enum types in MutationReceipt.
notification_event
Nested message and enum types in NotificationEvent.
notification_rule
Nested message and enum types in NotificationRule.
o_auth_proof
Nested message and enum types in OAuthProof.
operation_event
Nested message and enum types in OperationEvent.
operation_record
Nested message and enum types in OperationRecord.
ownership_event
Nested message and enum types in OwnershipEvent.
pack_extent
Nested message and enum types in PackExtent.
pairing_event
Nested message and enum types in PairingEvent.
pairing_initiation_binding
Nested message and enum types in PairingInitiationBinding.
pairing_record
Nested message and enum types in PairingRecord.
presence_event
Nested message and enum types in PresenceEvent.
provider_assembly_record
Nested message and enum types in ProviderAssemblyRecord.
provider_dial_route
Nested message and enum types in ProviderDialRoute.
provider_extent_event
Nested message and enum types in ProviderExtentEvent.
publication_receipt
Nested message and enum types in PublicationReceipt.
publish_content_client_frame
Nested message and enum types in PublishContentClientFrame.
publish_content_server_frame
Nested message and enum types in PublishContentServerFrame.
record_interaction_request
Nested message and enum types in RecordInteractionRequest.
registration_recovery_policy
Nested message and enum types in RegistrationRecoveryPolicy.
remote_link_record
Nested message and enum types in RemoteLinkRecord.
replicate_thread_request
Nested message and enum types in ReplicateThreadRequest.
replicate_thread_response
Nested message and enum types in ReplicateThreadResponse.
resolve_discussion_request
Nested message and enum types in ResolveDiscussionRequest.
resource_selector
Nested message and enum types in ResourceSelector.
review_coverage
Nested message and enum types in ReviewCoverage.
review_decision
Nested message and enum types in ReviewDecision.
revision_ref
Nested message and enum types in RevisionRef.
run_event
Nested message and enum types in RunEvent.
search_event
Nested message and enum types in SearchEvent.
search_request
Nested message and enum types in SearchRequest.
signup_invitation_resolution
Nested message and enum types in SignupInvitationResolution.
source_target_reference
Nested message and enum types in SourceTargetReference.
source_target_resolution
Nested message and enum types in SourceTargetResolution.
source_target_resolution_event
Nested message and enum types in SourceTargetResolutionEvent.
spool_creation_proof
Nested message and enum types in SpoolCreationProof.
spool_event
Nested message and enum types in SpoolEvent.
stream_frame
Nested message and enum types in StreamFrame.
submit_owner_transition_request
Nested message and enum types in SubmitOwnerTransitionRequest.
submit_recovery_proof_request
Nested message and enum types in SubmitRecoveryProofRequest.
submit_recovery_proof_response
Nested message and enum types in SubmitRecoveryProofResponse.
thread_audience_policy
Nested message and enum types in ThreadAudiencePolicy.
thread_control_authority
Nested message and enum types in ThreadControlAuthority.
thread_event
Nested message and enum types in ThreadEvent.
thread_list_event
Nested message and enum types in ThreadListEvent.
thread_ownership
Nested message and enum types in ThreadOwnership.
thread_query
Nested message and enum types in ThreadQuery.
thread_relationship
Nested message and enum types in ThreadRelationship.
transfer_sidecar
Nested message and enum types in TransferSidecar.
veto_recovery_request
Nested message and enum types in VetoRecoveryRequest.
workspace_event
Nested message and enum types in WorkspaceEvent.

Structs§

AcknowledgeCheckRequest
ActionAvailability
AgentRef
Stable delegated agent identity, scoped to its owning account. Neither a display name nor a rotating signing key is an agent’s resource identity.
AnalysisArtifact
Immutable derived analysis output. Stored under an opaque Thread-scoped artifact identity; this is never an authorization wrapper for source bytes. Readers decode one canonical message, not concatenated stream frames. The producer rejects outputs larger than its advertised artifact byte budget.
AnalysisEvent
AnalysisFinding
AnalysisRecord
AnnotationDecimal
Structured context metadata. References describe a target; they grant no access to it and never change the annotation’s primary anchor or audience.
AnnotationProperty
AnnotationPropertyPredicate
AnnotationQuery
AnnotationSourceReference
AnnotationSymbolTag
AnnotationTag
AnnotationTagPredicate
AnnotationValue
AnonymousSessionResponse
AppendDiscussionRequest
Applied
ApprovalGroupRecord
ApprovePairingRequest
ArtifactEvent
AttachProviderInstallationRequest
Attach a GitHub App installation that became available after OAuth consent. The hosted service validates the exact installation against the caller’s stored provider credential before updating the connection.
AttentionEvent
AttentionItem
AuthenticationChallenge
AuthenticationResponse
AuthorizationSignature
AuthorizationVerificationKey
BeginAuthenticationRequest
BeginCheckoutRequest
BeginEmailVerificationRequest
BeginPairingRequest
BeginPairingResponse
BeginProviderConnectionRequest
BeginRecoveryRequest
BeginRecoveryResponse
BeginRegistrationRequest
BehaviorAnalysisCoverage
BehaviorAssignment
BehaviorBinding
BehaviorBranch
BehaviorByteSpan
BehaviorChange
A self-contained structural map. Typed containment (assignment.value_id, conditional.predicate_id), selection (branches), binding and correspondence are distinct. This version emits no inferred consequences or test approval; resolved call/reference graph edges remain independent evidence and cannot establish execution order or effects. All referenced IDs must occur here.
BehaviorChangeRemoval
BehaviorConditional
BehaviorCorrespondence
BehaviorDependencies
BehaviorExpression
BehaviorOperation
BehaviorScope
Each entry describes only this analyzer’s supported pattern, not all behavior in a file or file group. Empty supported scope means no supported changes; omitted scope, partial analysis and interrupted streams are different states.
BehaviorSource
Source navigation is pinned to bytes, never just a semantic digest. Byte offsets are zero-based, half-open UTF-8 byte ranges. No inferred locations.
BehaviorVersions
BillingEvent
BillingPlan
BillingRecord
BillingRedirectResponse
BillingSeatPricing
BillingSeatTier
BlobChunk
BlobRead
Blocked
BookmarkMutationResponse
BookmarkRecord
BookmarkRef
Caller-private preference identity; changing it never changes its target.
BootstrapOwnershipRequest
BrowserPairingApprovalBinding
BrowserPairingCompletionBinding
SignedRecord format heddle.browser-pairing-completion.v1. The current subject key signs domain || deterministic protobuf bytes plus a fresh exact RPC proof.
BrowserPairingReceiver
Provisional two-key possession, before an approving account is known. SignedRecord format heddle.pairing-initiation.v2; each actual receiver key signs domain || protobuf bytes in ascending tag order, omitting scalar defaults. Oneof presence is preserved. The host and operation prevent reuse. Credential-only receiver. Its subject key is not an Iroh endpoint.
CancelOperationRequest
CancelSubscriptionRequest
CapabilityPrincipal
CaptureCheckoutRequest
CaptureSummary
CatalogActivitySummary
Counts of public activity on one catalog Spool. A server deriving these from rollups may serve eventually consistent values; they are display hints, not authorization or a transactional snapshot of underlying Threads/changes.
CatalogEvent
CausalFrontier
A causal frontier is portable within its exact Thread/facet/format. It is never an Observe cursor or a bulk-transfer checkpoint. Heads are paged using the negotiated max_items; repeated Have frames contribute to the same round.
ChangeThreadLifecycleRequest
CheckAcknowledgementRecord
Immutable review progress for one accepted check result and exact policy. This does not change its outcome, supersede evidence or grant landing approval.
CheckEvidenceSummary
Derived presentation of canonical signed evidence. The receiving endpoint verifies original authority independently; a reported pass is not itself cryptographic proof that an external process ran correctly.
CheckoutEvent
CheckoutMutationResponse
CheckoutOverview
CheckoutRef
CheckoutWriterLease
The same physical-checkout lease is enforced by CLI and device RPCs. Possessing its token never grants authority: each mutation also authenticates the owner session, verifies current capability, and compares source/version.
ClaimCheckoutWriterRequest
ClaimCheckoutWriterResponse
ClaimHandleRequest
ClaimHandleResponse
ClaimThreadOwnershipRequest
The owner and accepting account publisher co-sign one exact canonical claim. Upload and device enrollment never invoke this transition implicitly.
ClaimThreadOwnershipResponse
ClientOwnedCredential
CloneAuthorizationKeyring
CloneOwnerPin
Local provenance chosen and persisted by the client. There is no UUID-to-key migration or legacy TOFU arm: all accounts start owner-anchored.
CollaborationAnchor
CollaborationEvent
CompleteAuthenticationRequest
CompleteEmailVerificationRequest
CompleteEmailVerificationResponse
CompleteOwnerTransitionRequest
CompletePairingRequest
CompleteProviderConnectionRequest
CompleteRecoveryRequest
CompleteRegistrationRequest
ContentEvent
ContentFile
ContentRead
ContentSpoolLink
ContentTreeEntry
ContextDraft
Write input. Actor attribution is carried by the signed canonical operation; coverage and current-view versions are server projections, never client input.
ContextRecord
ControlRunRequest
CreateAnonymousSessionRequest
Anonymous continuity has no human account and no independent owner root. The endpoint retains its existing anti-abuse, expiry and rotation checks.
CreateBillingPortalRequest
CreateInvitationRequest
CreateInvitationResponse
CreateSignupInvitationRequest
CreateSignupInvitationResponse
CreateSpoolRequest
CredentialInspection
CredentialResult
Returned only by a successful credential ceremony, never by an observation. Keyed clients retain their own minting authority. Registration attaches their proved key to an account/session; it does not mint a bearer or confer an independent human root on an agent. Other keyless ceremonies can return an issued bearer. Password completion MUST return client_owned, never issued.
CurrentCredentialRecord
Metadata for the exact credential authenticating this observation. This is not issuance, and neither account tier nor account role upgrades its rights.
DecideRunPermissionRequest
DelegationCredentialResponse
DelegationRecord
DeleteAccountRequest
Irreversibly deletes the caller’s account. The authenticating credential MUST be the direct account owner’s proof-bearing credential: agent, service, delegated, derived and attenuated credentials are rejected even if they otherwise carry caller-bound account authority. confirmation_handle MUST exactly equal the account’s current handle. Reusing client_operation_id returns the original outcome without deleting or canceling anything twice.
DeleteAccountResponse
DeleteApprovalGroupRequest
DeletePasswordOwnerSetupRequest
DeleteReviewPolicyRequest
DeleteSpoolRequest
DescribeEndpointRequest
DescribeEndpointResponse
DeviceIdentity
DiffRead
DiscussionRecord
DiscussionTurn
EmailVerificationChallenge
Only the endpoint’s authenticated, independently rooted signup-mailer service account may begin delivery. Its bearer is the possession factor.
EndpointRef
EntitlementRecord
EntityRef
EvidenceRecord
EvidenceVerification
ExpectedVersion
FetchClientFrame
FetchComplete
FetchOpen
FetchServerFrame
GetIdentityRequest
Bounded unary identity lookup for one-shot callers. The principal is always returned; callers can opt into metadata for the authenticating credential.
GetIdentityResponse
GrantRecord
GroupRequirement
GuardianRecoveryPolicySelection
Registration defaults to this guardian M-of-N policy. If OwnerRegistration.recovery is absent, the policy in the signed root is treated as this branch and MUST contain a valid threshold and at least one non-WEFT guardian. Absence never selects Weft custody.
HandleResolution
HarnessPreference
IdentityEvent
ImportSourceRequest
IntegrationEvent
IntrospectCredentialRequest
InvitationQuota
InvitationRecord
InvitationResolution
IssueDelegationCredentialRequest
Creating/updating a delegation record and issuing a credential are different effects. The caller must prove the active delegation authority; the new key must prove possession. Scope/expiry cannot exceed the accepted delegation.
IssuedCredential
LandCheckoutRequest
LandStackRequest
LandThreadRequest
LandingAssessment
ListSpoolsRequest
Grant-reachable unary Spool listing for whoami and admin surfaces. ObserveWorkspace remains the live composed workspace view; this RPC is the bounded one-shot catalog of Spools reachable through the caller’s grants. repos_only keeps content-bearing (repository/project) rows.
ListSpoolsResponse
ListedSpool
MarkNotificationsReadRequest
MaterialRetention
MaterializeCheckoutRequest
MemberRecord
MintRootAttachment
Public association of a credential mint root with one exact owner authority state. This grants no operations: ordinary Biscuit checks remain mandatory. Canonical v1 fields follow tag order using fixed-width/length-prefixed encoding. Domain: “heddle-mint-root-attachment-v1”.
Money
MutationReceipt
MutationResponse
NotificationDigestOverride
NotificationEvent
NotificationPreferences
NotificationRecord
NotificationRule
OAuthProof
ObjectAddress
These are native v2 transfers, not envelopes carrying v1 Push/Pull requests. A signed opening binds exact v2 scope, operation, policy, inventory and resume context. Packs and indexes travel as bounded protobuf chunks under flow control.
ObserveAnalysisRequest
ObserveAttentionRequest
ObserveBillingRequest
ObserveCatalogRequest
ObserveCheckoutsRequest
ObserveCollaborationRequest
ObserveIdentityRequest
ObserveIntegrationsRequest
ObserveNotificationsRequest
ObserveOperationsRequest
ObserveOptions
ObserveOwnershipRequest
ObservePairingRequest
ObserveRunsRequest
ObserveSpoolRequest
ObserveThreadRequest
ObserveThreadsRequest
ObserveWorkspaceRequest
OpenDiscussionRequest
OperationEvent
OperationRecord
OwnerAuthorizationBundle
OwnerCapability
OwnerHistory
This local persistence wrapper is not served as clone-readiness evidence. PullReady carries SignedSpoolOwnerGenesis; after TOFU-pinning it, the client constructs this keyring from the verified root and state-tree transition entries. Loading it recomputes every id/hash and verifies the full chain; unknown versions, gaps, duplicate sequences, forks, owner-id mismatch, or capabilities for another spool fail closed. Portable proof of one exact owner-key state, including historical states used by resource transfers. Several states of the same owner may appear.
OwnerKeyBinding
Self-asserted attachment of a root key to the stable owner UUID. stable_owner_uuid is exactly 16 bytes and never changes. challenge_nonce is exactly 32 bytes, single-use, and scoped by the service to the authenticated principal and UUID. binding_epoch begins at one and increases monotonically.
OwnerKeyTransition
OwnerRegistration
OwnerRoot
OwnerState
Account authority and resource ownership are separate. A root can be established before a spool exists. A spool’s genesis/transfer chain refers to that authority without changing the resource identity.
OwnerTransitionRecord
A persisted proposal is distinct from an accepted owner state. Its original signatures remain independently verifiable; version governs complete/veto.
OwnerTransitionResponse
Submission durably records a proposal. A later distinct operation completes it after its signed veto window; retrying submission never commits it.
OwnershipEvent
PackChunk
PackExtent
PageInfo
PageRequest
PairingEvent
PairingInitiationBinding
PairingRecord
PaperCodeKdfMaterial
PaperCodeUnlock
PasskeyAuthority
Current owner authorization for a passkey to attach temporary Ed25519 mint keys. This certifies key lineage, not operations: Biscuit attenuation, resource audience and current revocation remain mandatory. It confers no independent owner/root-establishment authority. Canonical fields follow tag order using fixed-width/length-prefixed encoding; domain “heddle-passkey-authority-v1”.
PasskeyMintDelegation
PasskeyMintGrant
Account-free request for one passkey to authorize a temporary Ed25519 mint key. Canonical v1 fields follow tag order using fixed-width/length-prefixed encoding. Domain: “heddle-passkey-mint-grant-v1”. The WebAuthn challenge is SHA-256(domain || canonical fields). Account and owner fields are deliberately absent and MUST be derived from PasskeyMintDelegation.authority.
PasskeyProof
PasskeyRecord
Account-private passkey inventory, requested through ObserveIdentity. The certificate is public verification material; no credential private key or reusable assertion is returned. Device registration is a separate lifecycle.
PasskeyRegistration
PasswordChallengeMetadata
Only returned for PASSWORD. Every handle without an active password setup (unknown, passkey-only, deleted, or disabled) gets indistinguishable public metadata: salt derived deterministically from a server secret and the canonical handle, with the same costs, KDF/version, and response shape. Challenge IDs/nonces remain fresh. The server binds the account internally, never via a handle-to-UUID value at begin. Creation is throttled; expiry <= 10 minutes.
PasswordChallengeProof
Proof of the public password verifier only. This message is never accepted by CompleteAuthentication, an owner mutation, or a credential issuer. Ed25519 signs SHA-256(“heddle-password-proof-v1” || canonical transcript): challenge_id[32] || nonce[32] || caller_device_public_key[32] || u32be(operation_id UTF-8 byte length) || operation_id UTF-8 || i64be(expiry Unix seconds). No protobuf is signed. The server’s one-use challenge record binds the current envelope revision; it is returned only with the continuation after successful proof.
PasswordDeviceAdmission
The owner signs this exact admission, independently of the password proof. Ed25519 signs SHA-256(“heddle-password-device-admission-v1” || u32be(format_version) || account_uuid[16] || challenge_id[32] || continuation_id[32] || caller_device_public_key[32] || owner_state_hash[32] || u64be(owner_sequence) || u32be(client_operation_id UTF-8 byte length) || client_operation_id UTF-8).
PasswordOwnerEnvelopeV1
Encrypted 32-byte Ed25519 owner seed. The server stores and returns these opaque bytes, never a password, KEK, auth seed, or decrypted owner seed. Reject unknown versions/KDFs before use. Discard unknown protobuf fields and persist only the canonical re-encoding of known fields (<= 4096 bytes). AES-GCM AAD is ASCII(“heddle-owner-wrap-aad-v1”) || 0x00 || u32be(version) || account_uuid || owner_public_key || owner_id || u32be(kdf_id) || u32be(memory_kib) || u32be(iterations) || u32be(parallelism) || wrap_salt.
PasswordOwnerSetup
Public authentication metadata, stored separately from the encrypted seed. Client input is UTF8(NFC(password)), preserving case and all spaces. Client guidance is 15+ Unicode characters and at most 1024 UTF-8 bytes; the server cannot enforce strength without seeing the password. The independent inputs are UTF8(“heddle-password-auth-v1”) || 0x00 || UTF8(NFC(password)) with auth_salt, and UTF8(“heddle-owner-wrap-v1”) || 0x00 || UTF8(NFC(password)) with wrap_salt. Both use the recorded Argon2id costs and 32-byte output. Only the Ed25519 public key derived from auth_seed crosses the network. Discard unknown fields, including nested envelope fields, and persist only the canonical re-encoding of known fields (<= 4608 bytes). The verifier and owner keys MUST be canonical, decompressible, and non-small-order. Ed25519 signatures use strict verification: canonical R and S, non-small-order points, and the standard group equation. Rust uses verify_strict; WebCrypto callers MUST precheck these conditions before its verify operation.
PasswordOwnerSetupAuthorization
Owner authorization for changing the password envelope. The owner signs SHA-256(“heddle-password-owner-setup-change-v1” || u32be(format_version) || u32be(action) || account_uuid[16] || owner_state_hash[32] || u64be(expected_revision) || setup_sha256[32] || u32be(client_operation_id UTF-8 byte length) || client_operation_id || i64be(expires_at Unix seconds)). expires_at has zero nanos and is future, with a bounded lifetime of at most 10 minutes from issuance. setup_sha256 is SHA-256 of the fixed-order v1 setup fields (the envelope’s fields in tag order, followed by auth_salt, verifier key, auth costs, auth_kdf_id and format_version; the possession signature is excluded), with byte fields raw and integers big-endian. DELETE uses 32 zero bytes. The current active account UUID, owner public key and owner ID MUST equal the setup envelope fields. Both actions CAS the account-lifetime revision. A successful PUT or DELETE atomically increments it and invalidates every outstanding password challenge and continuation. DELETE retains a tombstone revision; re-setup CASes against that value. Revision 0 is allowed only when no password setup has ever existed for this account; no revision is reused.
PasswordUnlockCompletion
PasswordUnlockContinuation
One-use delivery receipt, never a session, bearer, owner authorization or Biscuit. The continuation is bound to the challenge, revision, account and caller device, expires with the challenge, and is consumed at completion.
PinnedSourceTargetRevision
PrepareAccountClaimRequest
Device-local consent for claiming an agent-rooted human account. Browser possession and the explicit claim authorization are both required. Weft independently verifies the registration; the device never submits it.
PrepareAccountClaimResponse
PresenceEvent
Presence session fan-out events for Track B /presence/ws.
PrincipalRecord
PrincipalRef
PromoteSpoolRequest
Move a personal-root child to the account’s root-level address at its current slug. UUID, genesis, descendants, and direct grants survive. Bound by the destination ancestry’s effective max_audience: refuse promotion that would place a too-wide child under a tighter destination. Birth-parent lock does not follow the promoted spool.
ProposedHumanAction
ProvePasswordUnlockRequest
ProvenanceRead
ProvenanceResult
ProviderAssemblyRecord
One record in output-pack order. Provider bytes must occupy an exact tiled physical range; inline bytes arrive as bounded ProviderInlineChunk frames. In either case the client verifies the encoded bytes and decoded object.
ProviderChallenge
ProviderConnection
ProviderConsent
ProviderDialRoute
Authenticated transport hints only. The connected Iroh peer must still match provider.public_key; a URL is never a source of authority.
ProviderExtent
ProviderExtentEvent
ProviderInlineChunk
ProviderInlineSource
ProviderOffer
ProviderOfferExtent
Capability-free candidate layout. It is not a serving grant. The client consents to its exact challenge before the issuer publishes ticket-bearing ProviderPlan; both phases use the same canonical layout commitments.
ProviderPackLocation
Trusted issuer-to-provider control-plane registration. Never sent over the client Fetch stream. object_key names a private provider bucket object and must not appear in a client-visible ProviderPlan or ReadProviderExtent.
ProviderPhysicalRange
A physical R2 range exactly tiled by independently hashed encoded records. record_set_commitment is a metadata commitment over pack identity, offset, length and ordered encoded record digests; it is not a hash of range bytes.
ProviderPlan
ProviderPlanChallenge
An unsigned challenge carried over an already authenticated Fetch stream. Only the client’s exact-plan consent is signed. Both digests and the selected Thread/revision bind all tickets and virtual-pack placement.
ProviderPlanRegistration
ProviderPlanRegistrationReceipt
ProviderRangeChunk
ProviderRangeSource
ProviderReadTicket
The provider verifies this typed ticket against the published canonical extent set and the attenuated caller capability. A ticket alone grants no access; the opening’s native request proof binds the bearer key, the authenticated Iroh client peer matches client, and the receiver’s endpoint matches provider. Root rotation and expiry are independently checked.
ProviderRepository
ProviderResult
ProvisionAccountRequest
Invite-gated creation of an unclaimed human account. The independent root slot stays empty. The agent proves its own key over this exact request using principal:device-key:; a human bearer cannot replace that proof. Existing key-bound accounts may be reused without an invitation. Reusing an operation ID with different bytes is rejected.
ProvisionAccountResponse
PublicHandleRecord
Public directory metadata contains no stable subject/account identifiers. ResolveResources supplies those only within an authorized resource scope.
PublicOwner
A display label for a publicly visible catalog row. Neither field grants access or supplies an owner verification key.
PublicPrincipalSummary
Public presentation only; never carries credential, account settings or rights.
PublicationReceipt
PublishContentClientFrame
PublishContentFinish
PublishContentOpen
Bulk content availability for an already admitted Thread capture. Metadata replication owns causal heads; uploading bytes cannot select or replace one. The opening PoP binds the exact Thread/revision, policy, complete pack/index addresses and lengths, operation identity, and any resume checkpoint.
PublishContentServerFrame
PurgeOperationSigningBody
Protobuf serialization is never signed. canonical_purge_operation_v2 is: u32_be(format_version), raw 16-byte spool_uuid, blob_hash as a u32-length- prefixed string, raw 32-byte payload_sha256, raw 32-byte leaf_capability_id. The leaf subject signs SHA-256(“heddle-purge-operation-v2” || canonical_body). The verifier binds this body to the actual spool, payload and direct PURGE grant. Moving the RPC package does not change this durable signing format.
PurgeSidecarIdentity
PutApprovalGroupRequest
PutContextRequest
PutDelegationRequest
PutGrantRequest
PutPasswordOwnerSetupRequest
PutRecoveryPolicyRequest
PutReviewPolicyRequest
PutRunPolicyRequest
ReadArtifactRequest
ReadBudget
ReadContentRequest
ReadProviderExtentRequest
RecordEvidenceRequest
RecordInteractionRequest
RecordRef
RecordReviewRequest
RecordSignature
RecoverCheckoutRequest
RecoveryArgon2idParams
RecoveryAttempt
RecoveryGuardian
RecoveryPolicy
The owner precommits to a threshold over distinct dedicated guardian keys. Product policy defaults to threshold >= 2 and a device-independent co-factor whenever Weft is a guardian. A 1-of-1 Weft policy is custodial and is allowed only after the client obtains the separately reviewed explicit confirmation.
RedeemInvitationRequest
RedeemSignupInvitationRequest
A held shareable invitation code selects the admission directly; no lookup RPC, account bearer or device root is needed before choosing a passkey.
RedeemSignupInvitationResponse
RefreshCheckoutRequest
RegisterRootAttachmentRequest
RegistrationChallenge
RegistrationRecoveryPolicy
ReleaseCheckoutWriterRequest
RemoteLinkRecord
Removal
RemoveSpoolMountRequest
RenameThreadRequest
RenewEphemeralSessionRequest
Renews a short-TTL ephemeral (declined-enrollment) session in place. The renewal is proven by the caller’s existing ephemeral bearer plus a request PoP signed by the ephemeral key (CallContext.request_proof), so the body carries no session ref: the renewed session is exactly the caller’s own.
RenewEphemeralSessionResponse
ReopenDiscussionRequest
ReplicateThreadRequest
ReplicateThreadResponse
ReplicationHave
ReplicationNeed
ReplicationOpen
ReplicationOperations
ReplicationReady
ReplicationReceipt
ReplicationRejection
RequestHeldHandleRequest
RequestHeldHandleResponse
Requirement
ResolveCheckoutRequest
ResolveDiscussionRequest
ResolveHandlesRequest
ResolveHandlesResponse
ResolveInvitationRequest
Public capability preview. The invitation ID alone reveals nothing; the redemption secret is passed in the request body and never placed in a URL path or query. No recipient email or inviter identity is disclosed.
ResolveOwnershipConflictRequest
The original local owner chooses the winning account; that account’s currently authorized owner or delegate accepts. Neither arrival order nor a claimant’s signature alone adjudicates the conflict. Never implicit in upload/enrollment.
ResolveResourcesRequest
ResolveResourcesResponse
ResolveSignupInvitationRequest
ResourceOwnershipTransfer
Complete client-authored transfer. Missing either signature fails closed.
ResourceResolution
ResourceSelector
Account names and paths resolve to stable resources once. They never become authorization roots or replace the stable IDs in subsequent commands.
ResourceTransferAcceptance
ResourceTransferAuditRecord
Append-only result committed atomically with the resource-to-owner re-anchor. audit_record_hash is SHA-256(“heddle-resource-transfer-audit-v1” || the canonical transfer, commit time, and previous audit hash).
ResourceTransferHandoff
Canonical source offer for an atomic resource ownership re-anchor. canonical_resource_transfer_handoff_v1 encodes fields 1 through 8 in field order using fixed-width big-endian integers and length-prefixed byte strings. UUIDs are exactly 16 bytes, state hashes and nonce are exactly 32 bytes.
ResumeSubscriptionRequest
RetryImportSourceRequest
Retry a failed native source fetch/adoption into its original Thread. The original operation remains immutable; this command creates a new operation and never creates a second Spool or Thread genesis.
ReviewComparison
Exact comparison resolved within a review-section snapshot. A client submits these source/base/policy bytes when recording a decision; a Thread’s genesis base and an arbitrary source head are not substitutes for this binding.
ReviewCoverage
ReviewDecision
ReviewPolicyRecord
ReviewRecord
The observed decision and the exact portable signed control that authored it.
ReviewSymbolAnchor
ReviewSymbols
ReviseIntentRequest
ReviseSpoolRequest
Compare and replace display name and complete settings atomically. The stable UUID, parent, and immutable owner genesis are unchanged. Owner signature is not a prerequisite. The mere existence of a signed-policy tip does not block this RPC (independent CAS from expected_head). settings.audience / default_state_audience are bounded by the standing inherited max_audience (this spool and ancestors). Exceeding it is PERMISSION_DENIED.
RevisionRef
RevokeDelegationRequest
RevokeDeviceRequest
RevokeGrantRequest
RevokeInvitationRequest
RevokeProviderConnectionRequest
RevokeSessionRequest
RootAttachment
User-root proof is portable. Account association records Weft’s acceptance of an already user-authorized key; it is not the source of that key’s authority.
RootAttachmentBinding
Portable binding of a proved delegated key to its Iroh endpoint. Authority remains the Biscuit’s complete attenuation chain, not this locator binding. SignedRecord format heddle.root-attachment.v2 carries canonical bytes signed by both endpoint and subject (one signature when the keys are equal). The shared verifier requires a locally trusted root, verifies the Biscuit’s effective proof key and limits, then verifies digest, time and endpoint.
RunArtifact
RunEvent
RunPermission
RunPolicy
RunRecord
SearchDomainStatus
Per-domain readiness is independent of result count and hidden matches. An unavailable index is not represented as an empty, complete result set.
SearchEvent
SearchHit
SearchRequest
SectionReplacement
SectionStatus
SemanticIndexArtifact
Self-contained derived index, readable in one bounded artifact stream. Nodes are unique and sorted by hash; root_hash is 32 bytes and must name an included root. All derived root/tree/file nodes are included and verified. Opaque file entries may identify source commitments, but their raw source bytes are never included. Parsed/opaque counts describe this exact source.
SemanticIndexObject
One existing Heddle semantic root/file/directory object. The canonical bytes use the versioned Heddle semantic index codec. The 32-byte hash uses Heddle’s Blob identity: BLAKE3(UTF8(“blob”) || uint64_le(canonical.length) || 0x00 || canonical), matching Blob::hash(). Hashing canonical alone is incorrect. This object grants no right to fetch other CAS objects.
SessionRecord
SetAttentionStateRequest
SetBookmarkRequest
SetNotificationPreferencesRequest
SetRemoteLinkRequest
SetSpoolMountRequest
SetSupportAccessRequest
SetThreadAudienceRequest
SetThreadRetentionRequest
SetThreadSharingRequest
SharingDestination
SidecarAuthorization
Portable authorization for an exact purge, independently of its transport.
SignAccountClaimRequest
SignAccountClaimResponse
SignedMintRootAttachment
Portable owner -> passkey -> temporary mint-key authorization. This v2 shape is the only SignedMintRootAttachment accepted for passkey sign-in.
SignedOwnerCapability
SignedOwnerKeyTransition
Authorizations sign canonical_owner_key_transition_v1(transition).
SignedOwnerMintRootAttachment
Owner-signed account-bound attachment retained for registration of a durable independent mint root. Passkey authentication never accepts this shape: its account-free grant and owner-certified passkey chain use SignedMintRootAttachment below.
SignedOwnerRoot
SignedPasskeyAuthority
SignedPasswordDeviceAdmission
SignedPasswordOwnerSetupAuthorization
SignedPolicyBody
SignedPolicyHead
CAS predecessor. Independent of ReviseSpool.expected_version. Zero hash + sequence 0 = genesis.
SignedPolicyMergeRule
SignedRecord
A durable, versioned record. Its format defines canonical bytes, domain, signature algorithm, bounds and verifier. Generic protobuf serialization is never the signing input. Unknown critical formats fail closed.
SignedResourceTransferHandoff
SignedSpoolOwnerGenesis
Self-signed genesis evidence. owner_signature.signer_key_id MUST identify genesis.owner_public_key, and that key signs the exact 32-byte digest:
SignedSpoolPolicy
Offline-verifiable, owner-gated payload. NOT a copy of SpoolSettings. Substantive content: grow-only revocations + max_audience ceiling.
SignedSpoolPolicyRecord
SignupInvitation
SignupInvitationResolution
SignupReservation
SourceAnchor
SourceConflictCandidate
SourceConflictSet
A bounded set of immutable source alternatives observed at one checkout version. Candidate IDs are opaque and only meaningful within this version.
SourceLocation
Exact current coordinates, never an authoring input or a replacement for the original evidence in SourceAnchor. No implicit tracking from these fields.
SourceOperationFrontier
SourceTargetReference
Shared by primary anchors and annotation references. This is a reference, never a grant to read the target’s source or its owning Thread.
SourceTargetResolution
SourceTargetResolutionEvent
Shared map updates for anchors and tags. Snapshot/Upsert frames carry upsert; Remove frames carry remove. Deduplicate by key within a checkpoint batch. Maps clear with Thread collaboration / Spool context section replacement and replacement snapshots. Remove the entry when its last referrer leaves the observed window. Neither missing targets nor these events grant source access.
SourceTargetResolutionKey
Stable within an endpoint observation. Only a viewed_thread binding requires viewed_thread here; named and pinned bindings MUST omit it. The selected revision is a value, so capture moves one shared entry, not every referrer.
SourceTargetView
Exact view selection for a Thread’s inherited target bindings. This selects resolution only; it grants no source access and does not select more records.
SpoolAddress
Observed address of a stable Spool identity. Renames change the address, never the UUID. An address is presentation/routing metadata, not authority.
SpoolCapabilityGrant
SpoolCreationProof
SpoolCreationStatement
A creator’s statement of exact intended creation. created_at is NOT an admission timestamp. Only actual current admission or independently retained accepted evidence establishes whether this creation was permitted then. Canonical v1 fields follow tag order; domain “heddle-spool-creation-v1”.
SpoolEvent
SpoolMount
SpoolMutationResponse
Committed overview and independently verifiable owner history seed the caller’s view directly. The receipt is not a trust root or a TOFU pin.
SpoolOverview
SpoolOwnerGenesis
Immutable owner-key binding created with a spool. spool_uuid is the raw 16-byte UUIDv7 that is also the spool id. owner_public_key is the owner authority key at creation; no registry key or nonce participates.
SpoolPages
SpoolRef
SpoolSelector
SpoolSettings
Fresh bootstrap permits child creation and has no implicit approval mandate. Explicit review policies still apply. A revision supplies the complete record; its settings participate in the observed review policy version.
StackLanding
Each source is the exact revision supplied by the caller. For every distinct target, expected_target is compared once against the initial transaction snapshot. Ordered members then integrate into that target’s evolving frontier.
StartAnalysisRequest
StartThreadRequest
StateRead
Exact immutable source summary. Authored sidecars (including risk signals, conflict resolutions and semantic attachment attribution) are not source objects: use audience-checked Thread, checkout and Analysis projections. The selection emits one StateSummary followed by selection_complete.
StoreProviderCredentialRequest
StreamCheckpoint
StreamComplete
StreamData
StreamFrame
StreamHeartbeat
StreamOpen
StreamReset
SubmitOwnerCapabilityRequest
SubmitOwnerTransitionRequest
SubmitRecoveryProofRequest
SubmitRecoveryProofResponse
SubmitSignedPolicyRequest
Owner-signed spool policy submit. Not a prerequisite of ReviseSpool. request.spool MUST equal record.body.spool_uuid; mismatch fails closed. Proposed max_audience, if present and specified, MUST be <= the ancestors’ effective ceiling (min over ancestors only). Retry by client_operation_id. The biscuit RESOURCE_OWNER role is necessary but not sufficient: the verifier checks the owner signature against the server-derived current owner OwnerState. Receipt binds SignedPolicyHead (Decision 8).
SubmitSignedPolicyResponse
SupportAccessRecord
SynchronizeRemoteRequest
ThreadAudiencePolicy
ThreadControlAuthority
Original author evidence bound into each signed Thread metadata operation. Supplied history never establishes trust: receivers verify against separately admitted current account authority at first durable admission. Canonical protobuf encoding is mandatory and the entire envelope is bounded to 64 KiB.
ThreadEvent
One typed stream composes a Thread’s decision context. Common frame controls have no payload. Every data frame carries exactly one payload; snapshots and delta batches become visible only at their checkpoint. SectionReplacement.section and SectionStatus.section use these exact keys: overview (overview); captures (capture); review (comparison, review, diff); evidence (evidence, check_acknowledgement); collaboration (discussion, turn, context, source_target); analysis (analysis); checkouts (checkout); timeline (timeline_event, run, operation); sharing (sharing, publication). Replacement clears only that section’s committed collection. Unknown section semantics require a fresh supported view, never silent loss.
ThreadGenesisRecord
Carries original ownership proof with the immutable creator-signed identity. The receiver independently verifies it; transport credentials never select the owning account or enroll an otherwise-untrusted account root.
ThreadId
ThreadIntent
ThreadInvitee
ThreadListEvent
ThreadMetadataConflict
ThreadMutationResponse
ThreadNameSelector
ThreadOverview
ThreadOwnership
ThreadOwnershipConflict
ThreadPages
Independent section windows share one observation’s total read budget. Missing windows select bounded defaults only for requested sections.
ThreadPropertyFrontier
ThreadQuery
ThreadRef
ThreadRelationship
ThreadRetentionPolicy
ThreadSharingPolicy
TimelineRecord
TransferCheckpoint
TransferObject
TransferOwnershipRequest
TransferReady
TransferSelection
TransferSidecar
TreeRead
UnsubscribeNotificationsRequest
Public, single-purpose disabling action. The opaque capability determines the recipient and exact allowed selectors; no account credential is required. Each requested rule must select an authorized channel and DISABLED delivery.
UpdateSubscriptionRequest
VerifiedEmailReservation
VerifyEvidenceRequest
VerifyEvidenceResponse
VetoOwnerTransitionRequest
VetoRecoveryRequest
WeftCustodyRecoveryPolicySelection
The only supported custodial recovery shape is exactly one WEFT guardian with threshold one. It is never inferred from an omitted selection.
WeftCustodyWarningConsent
Versioned evidence that the user saw and accepted the exact 1-of-1 Weft custody warning. warning_sha256 is SHA-256 of the reviewed UTF-8 warning text for warning_version; unknown versions and digests fail closed.
WorkspaceEvent
WorkspacePages

Enums§

AccountDeletionOutcome
AnalysisKind
Audience
Existence/history audience for a spool. Numeric tags match v1 Visibility (PRIVATE=1, INTERNAL/MEMBERS=2, PUBLIC=3). Do not add AUDIENCE_INTERNAL.
AuthorizationKeyAlgorithm
BehaviorCorrespondenceKind
BehaviorLimitation
BehaviorMatchReason
BehaviorProvenance
BehaviorSupport
BillingInterval
CapabilityPrincipalKind
CatalogSort
Public resource discovery never includes private grants, devices or account attention. Exact public content still uses the ordinary resource read APIs.
CloneOwnerPinKind
Coverage
CredentialKind
CredentialMethod
Explicit ceremony selection; omitted or unsupported methods are rejected. Password unlocks a client-held owner key; OAuth retains its own ceremony. Neither a password verifier signature nor an OAuth proof is owner authority.
EndpointKind
HandleKind
HoldLifecycle
Delegated HOLD-verdict lifecycle on SpoolSettings. Not abandoned_thread_retention. v1 VersionedHoldLifecycle was chain-inherited and offline-citable; moving HOLD here drops that citation. UNSPECIFIED inherits; the built-in root default is EXPLICIT_SUPERSESSION.
OAuthProvider
ObservationMode
Shared observation protocol. Each RPC has a typed event payload alongside StreamFrame. Only a data frame carries a payload. See docs/alpha-v2/streams.md. A logical RPC occupies one reliable, ordered Iroh stream; this contract does not turn protobuf frames into unreliable UDP datagrams.
OwnerKeyBindingKind
OwnerKeyTransitionKind
RecoveryGuardianKind
Recovery-key provenance is part of the signed policy. A verifier can distinguish paper, social, and Weft guardians when counting signatures.
RequirementKind
ResourceRole
ReviewReadiness
RootingTier
Account onboarding state, never a substitute for a verified capability or owner-root binding. Promotions are explicit; a credential’s attenuation must survive promotion of its account. AGENT_ROOTED denotes an unclaimed human account with an empty independent-root slot, not an account owned by an agent.
SearchDomain
SearchMatchKind
How this match was established; score is only comparable within this query.
SearchSourceHistory
Which accepted source revisions participate in content and symbol search.
SeatPricingMode
SharedFacet
SignedPolicyMergeSemantics
SpoolCapabilityAction
SpoolSection
StreamDataKind
StreamResetReason
SubscriptionStatus
Provider IDs, API credentials and webhook secrets never appear in this contract. Weft resolves the authenticated account and checks the credential’s effective delegated billing authority for every read and mutation.
ThreadLifecycle
ThreadProperty
ThreadSection
TimelineStart
Selects where a single run’s timeline observation begins. This does not change the default oldest-first collection pagination.
UserVerification