Expand description
Frozen Thread-oriented contract; endpoint support is negotiated.
Modules§
- analysis_
event - Nested message and enum types in
AnalysisEvent. - analysis_
finding - Nested message and enum types in
AnalysisFinding. - annotation_
property_ predicate - Nested message and enum types in
AnnotationPropertyPredicate. - annotation_
tag - Nested message and enum types in
AnnotationTag. - annotation_
tag_ predicate - Nested message and enum types in
AnnotationTagPredicate. - annotation_
value - Nested message and enum types in
AnnotationValue. - artifact_
event - Nested message and enum types in
ArtifactEvent. - attention_
event - Nested message and enum types in
AttentionEvent. - attention_
item - Nested message and enum types in
AttentionItem. - begin_
pairing_ request - Nested message and enum types in
BeginPairingRequest. - begin_
registration_ request - Nested message and enum types in
BeginRegistrationRequest. - behavior_
assignment - Nested message and enum types in
BehaviorAssignment. - behavior_
branch - Nested message and enum types in
BehaviorBranch. - billing_
event - Nested message and enum types in
BillingEvent. - blob_
read - Nested message and enum types in
BlobRead. - bookmark_
ref - Nested message and enum types in
BookmarkRef. - catalog_
event - Nested message and enum types in
CatalogEvent. - check_
evidence_ summary - Nested message and enum types in
CheckEvidenceSummary. - checkout_
event - Nested message and enum types in
CheckoutEvent. - collaboration_
anchor - Nested message and enum types in
CollaborationAnchor. - collaboration_
event - Nested message and enum types in
CollaborationEvent. - complete_
authentication_ request - Nested message and enum types in
CompleteAuthenticationRequest. - complete_
pairing_ request - Nested message and enum types in
CompletePairingRequest. - complete_
registration_ request - Nested message and enum types in
CompleteRegistrationRequest. - content_
event - Nested message and enum types in
ContentEvent. - content_
read - Nested message and enum types in
ContentRead. - content_
tree_ entry - Nested message and enum types in
ContentTreeEntry. - control_
run_ request - Nested message and enum types in
ControlRunRequest. - create_
spool_ request - Nested message and enum types in
CreateSpoolRequest. - credential_
result - Nested message and enum types in
CredentialResult. - delegation_
record - Nested message and enum types in
DelegationRecord. - discussion_
record - Nested message and enum types in
DiscussionRecord. - entity_
ref - Nested message and enum types in
EntityRef. - fetch_
client_ frame - Nested message and enum types in
FetchClientFrame. - fetch_
open - Nested message and enum types in
FetchOpen. - fetch_
server_ frame - Nested message and enum types in
FetchServerFrame. - handle_
resolution - Nested message and enum types in
HandleResolution. - identity_
event - Nested message and enum types in
IdentityEvent. - integration_
event - Nested message and enum types in
IntegrationEvent. - invitation_
resolution - Nested message and enum types in
InvitationResolution. - material_
retention - Nested message and enum types in
MaterialRetention. - mutation_
receipt - Nested message and enum types in
MutationReceipt. - notification_
event - Nested message and enum types in
NotificationEvent. - notification_
rule - Nested message and enum types in
NotificationRule. - o_
auth_ proof - Nested message and enum types in
OAuthProof. - operation_
event - Nested message and enum types in
OperationEvent. - operation_
record - Nested message and enum types in
OperationRecord. - ownership_
event - Nested message and enum types in
OwnershipEvent. - pack_
extent - Nested message and enum types in
PackExtent. - pairing_
event - Nested message and enum types in
PairingEvent. - pairing_
initiation_ binding - Nested message and enum types in
PairingInitiationBinding. - pairing_
record - Nested message and enum types in
PairingRecord. - presence_
event - Nested message and enum types in
PresenceEvent. - provider_
assembly_ record - Nested message and enum types in
ProviderAssemblyRecord. - provider_
dial_ route - Nested message and enum types in
ProviderDialRoute. - provider_
extent_ event - Nested message and enum types in
ProviderExtentEvent. - publication_
receipt - Nested message and enum types in
PublicationReceipt. - publish_
content_ client_ frame - Nested message and enum types in
PublishContentClientFrame. - publish_
content_ server_ frame - Nested message and enum types in
PublishContentServerFrame. - record_
interaction_ request - Nested message and enum types in
RecordInteractionRequest. - registration_
recovery_ policy - Nested message and enum types in
RegistrationRecoveryPolicy. - remote_
link_ record - Nested message and enum types in
RemoteLinkRecord. - replicate_
thread_ request - Nested message and enum types in
ReplicateThreadRequest. - replicate_
thread_ response - Nested message and enum types in
ReplicateThreadResponse. - resolve_
discussion_ request - Nested message and enum types in
ResolveDiscussionRequest. - resource_
selector - Nested message and enum types in
ResourceSelector. - review_
coverage - Nested message and enum types in
ReviewCoverage. - review_
decision - Nested message and enum types in
ReviewDecision. - revision_
ref - Nested message and enum types in
RevisionRef. - run_
event - Nested message and enum types in
RunEvent. - search_
event - Nested message and enum types in
SearchEvent. - search_
request - Nested message and enum types in
SearchRequest. - signup_
invitation_ resolution - Nested message and enum types in
SignupInvitationResolution. - source_
target_ reference - Nested message and enum types in
SourceTargetReference. - source_
target_ resolution - Nested message and enum types in
SourceTargetResolution. - source_
target_ resolution_ event - Nested message and enum types in
SourceTargetResolutionEvent. - spool_
creation_ proof - Nested message and enum types in
SpoolCreationProof. - spool_
event - Nested message and enum types in
SpoolEvent. - stream_
frame - Nested message and enum types in
StreamFrame. - submit_
owner_ transition_ request - Nested message and enum types in
SubmitOwnerTransitionRequest. - submit_
recovery_ proof_ request - Nested message and enum types in
SubmitRecoveryProofRequest. - submit_
recovery_ proof_ response - Nested message and enum types in
SubmitRecoveryProofResponse. - thread_
audience_ policy - Nested message and enum types in
ThreadAudiencePolicy. - thread_
control_ authority - Nested message and enum types in
ThreadControlAuthority. - thread_
event - Nested message and enum types in
ThreadEvent. - thread_
list_ event - Nested message and enum types in
ThreadListEvent. - thread_
ownership - Nested message and enum types in
ThreadOwnership. - thread_
query - Nested message and enum types in
ThreadQuery. - thread_
relationship - Nested message and enum types in
ThreadRelationship. - transfer_
sidecar - Nested message and enum types in
TransferSidecar. - veto_
recovery_ request - Nested message and enum types in
VetoRecoveryRequest. - workspace_
event - Nested message and enum types in
WorkspaceEvent.
Structs§
- Acknowledge
Check Request - Action
Availability - Agent
Ref - Stable delegated agent identity, scoped to its owning account. Neither a display name nor a rotating signing key is an agent’s resource identity.
- Analysis
Artifact - Immutable derived analysis output. Stored under an opaque Thread-scoped artifact identity; this is never an authorization wrapper for source bytes. Readers decode one canonical message, not concatenated stream frames. The producer rejects outputs larger than its advertised artifact byte budget.
- Analysis
Event - Analysis
Finding - Analysis
Record - Annotation
Decimal - Structured context metadata. References describe a target; they grant no access to it and never change the annotation’s primary anchor or audience.
- Annotation
Property - Annotation
Property Predicate - Annotation
Query - Annotation
Source Reference - Annotation
Symbol Tag - Annotation
Tag - Annotation
TagPredicate - Annotation
Value - Anonymous
Session Response - Append
Discussion Request - Applied
- Approval
Group Record - Approve
Pairing Request - Artifact
Event - Attach
Provider Installation Request - Attach a GitHub App installation that became available after OAuth consent. The hosted service validates the exact installation against the caller’s stored provider credential before updating the connection.
- Attention
Event - Attention
Item - Authentication
Challenge - Authentication
Response - Authorization
Signature - Authorization
Verification Key - Begin
Authentication Request - Begin
Checkout Request - Begin
Email Verification Request - Begin
Pairing Request - Begin
Pairing Response - Begin
Provider Connection Request - Begin
Recovery Request - Begin
Recovery Response - Begin
Registration Request - Behavior
Analysis Coverage - Behavior
Assignment - Behavior
Binding - Behavior
Branch - Behavior
Byte Span - Behavior
Change - A self-contained structural map. Typed containment (assignment.value_id, conditional.predicate_id), selection (branches), binding and correspondence are distinct. This version emits no inferred consequences or test approval; resolved call/reference graph edges remain independent evidence and cannot establish execution order or effects. All referenced IDs must occur here.
- Behavior
Change Removal - Behavior
Conditional - Behavior
Correspondence - Behavior
Dependencies - Behavior
Expression - Behavior
Operation - Behavior
Scope - Each entry describes only this analyzer’s supported pattern, not all behavior in a file or file group. Empty supported scope means no supported changes; omitted scope, partial analysis and interrupted streams are different states.
- Behavior
Source - Source navigation is pinned to bytes, never just a semantic digest. Byte offsets are zero-based, half-open UTF-8 byte ranges. No inferred locations.
- Behavior
Versions - Billing
Event - Billing
Plan - Billing
Record - Billing
Redirect Response - Billing
Seat Pricing - Billing
Seat Tier - Blob
Chunk - Blob
Read - Blocked
- Bookmark
Mutation Response - Bookmark
Record - Bookmark
Ref - Caller-private preference identity; changing it never changes its target.
- Bootstrap
Ownership Request - Browser
Pairing Approval Binding - Browser
Pairing Completion Binding - SignedRecord format heddle.browser-pairing-completion.v1. The current subject key signs domain || deterministic protobuf bytes plus a fresh exact RPC proof.
- Browser
Pairing Receiver - Provisional two-key possession, before an approving account is known. SignedRecord format heddle.pairing-initiation.v2; each actual receiver key signs domain || protobuf bytes in ascending tag order, omitting scalar defaults. Oneof presence is preserved. The host and operation prevent reuse. Credential-only receiver. Its subject key is not an Iroh endpoint.
- Cancel
Operation Request - Cancel
Subscription Request - Capability
Principal - Capture
Checkout Request - Capture
Summary - Catalog
Activity Summary - Counts of public activity on one catalog Spool. A server deriving these from rollups may serve eventually consistent values; they are display hints, not authorization or a transactional snapshot of underlying Threads/changes.
- Catalog
Event - Causal
Frontier - A causal frontier is portable within its exact Thread/facet/format. It is never an Observe cursor or a bulk-transfer checkpoint. Heads are paged using the negotiated max_items; repeated Have frames contribute to the same round.
- Change
Thread Lifecycle Request - Check
Acknowledgement Record - Immutable review progress for one accepted check result and exact policy. This does not change its outcome, supersede evidence or grant landing approval.
- Check
Evidence Summary - Derived presentation of canonical signed evidence. The receiving endpoint verifies original authority independently; a reported pass is not itself cryptographic proof that an external process ran correctly.
- Checkout
Event - Checkout
Mutation Response - Checkout
Overview - Checkout
Ref - Checkout
Writer Lease - The same physical-checkout lease is enforced by CLI and device RPCs. Possessing its token never grants authority: each mutation also authenticates the owner session, verifies current capability, and compares source/version.
- Claim
Checkout Writer Request - Claim
Checkout Writer Response - Claim
Handle Request - Claim
Handle Response - Claim
Thread Ownership Request - The owner and accepting account publisher co-sign one exact canonical claim. Upload and device enrollment never invoke this transition implicitly.
- Claim
Thread Ownership Response - Client
Owned Credential - Clone
Authorization Keyring - Clone
Owner Pin - Local provenance chosen and persisted by the client. There is no UUID-to-key migration or legacy TOFU arm: all accounts start owner-anchored.
- Collaboration
Anchor - Collaboration
Event - Complete
Authentication Request - Complete
Email Verification Request - Complete
Email Verification Response - Complete
Owner Transition Request - Complete
Pairing Request - Complete
Provider Connection Request - Complete
Recovery Request - Complete
Registration Request - Content
Event - Content
File - Content
Read - Content
Spool Link - Content
Tree Entry - Context
Draft - Write input. Actor attribution is carried by the signed canonical operation; coverage and current-view versions are server projections, never client input.
- Context
Record - Control
RunRequest - Create
Anonymous Session Request - Anonymous continuity has no human account and no independent owner root. The endpoint retains its existing anti-abuse, expiry and rotation checks.
- Create
Billing Portal Request - Create
Invitation Request - Create
Invitation Response - Create
Signup Invitation Request - Create
Signup Invitation Response - Create
Spool Request - Credential
Inspection - Credential
Result - Returned only by a successful credential ceremony, never by an observation. Keyed clients retain their own minting authority. Registration attaches their proved key to an account/session; it does not mint a bearer or confer an independent human root on an agent. Other keyless ceremonies can return an issued bearer. Password completion MUST return client_owned, never issued.
- Current
Credential Record - Metadata for the exact credential authenticating this observation. This is not issuance, and neither account tier nor account role upgrades its rights.
- Decide
RunPermission Request - Delegation
Credential Response - Delegation
Record - Delete
Account Request - Irreversibly deletes the caller’s account. The authenticating credential MUST be the direct account owner’s proof-bearing credential: agent, service, delegated, derived and attenuated credentials are rejected even if they otherwise carry caller-bound account authority. confirmation_handle MUST exactly equal the account’s current handle. Reusing client_operation_id returns the original outcome without deleting or canceling anything twice.
- Delete
Account Response - Delete
Approval Group Request - Delete
Password Owner Setup Request - Delete
Review Policy Request - Delete
Spool Request - Describe
Endpoint Request - Describe
Endpoint Response - Device
Identity - Diff
Read - Discussion
Record - Discussion
Turn - Email
Verification Challenge - Only the endpoint’s authenticated, independently rooted signup-mailer service account may begin delivery. Its bearer is the possession factor.
- Endpoint
Ref - Entitlement
Record - Entity
Ref - Evidence
Record - Evidence
Verification - Expected
Version - Fetch
Client Frame - Fetch
Complete - Fetch
Open - Fetch
Server Frame - GetIdentity
Request - Bounded unary identity lookup for one-shot callers. The principal is always returned; callers can opt into metadata for the authenticating credential.
- GetIdentity
Response - Grant
Record - Group
Requirement - Guardian
Recovery Policy Selection - Registration defaults to this guardian M-of-N policy. If OwnerRegistration.recovery is absent, the policy in the signed root is treated as this branch and MUST contain a valid threshold and at least one non-WEFT guardian. Absence never selects Weft custody.
- Handle
Resolution - Harness
Preference - Identity
Event - Import
Source Request - Integration
Event - Introspect
Credential Request - Invitation
Quota - Invitation
Record - Invitation
Resolution - Issue
Delegation Credential Request - Creating/updating a delegation record and issuing a credential are different effects. The caller must prove the active delegation authority; the new key must prove possession. Scope/expiry cannot exceed the accepted delegation.
- Issued
Credential - Land
Checkout Request - Land
Stack Request - Land
Thread Request - Landing
Assessment - List
Spools Request - Grant-reachable unary Spool listing for whoami and admin surfaces.
ObserveWorkspace remains the live composed workspace view; this RPC is the
bounded one-shot catalog of Spools reachable through the caller’s grants.
repos_onlykeeps content-bearing (repository/project) rows. - List
Spools Response - Listed
Spool - Mark
Notifications Read Request - Material
Retention - Materialize
Checkout Request - Member
Record - Mint
Root Attachment - Public association of a credential mint root with one exact owner authority state. This grants no operations: ordinary Biscuit checks remain mandatory. Canonical v1 fields follow tag order using fixed-width/length-prefixed encoding. Domain: “heddle-mint-root-attachment-v1”.
- Money
- Mutation
Receipt - Mutation
Response - Notification
Digest Override - Notification
Event - Notification
Preferences - Notification
Record - Notification
Rule - OAuth
Proof - Object
Address - These are native v2 transfers, not envelopes carrying v1 Push/Pull requests. A signed opening binds exact v2 scope, operation, policy, inventory and resume context. Packs and indexes travel as bounded protobuf chunks under flow control.
- Observe
Analysis Request - Observe
Attention Request - Observe
Billing Request - Observe
Catalog Request - Observe
Checkouts Request - Observe
Collaboration Request - Observe
Identity Request - Observe
Integrations Request - Observe
Notifications Request - Observe
Operations Request - Observe
Options - Observe
Ownership Request - Observe
Pairing Request - Observe
Runs Request - Observe
Spool Request - Observe
Thread Request - Observe
Threads Request - Observe
Workspace Request - Open
Discussion Request - Operation
Event - Operation
Record - Owner
Authorization Bundle - Owner
Capability - Owner
History - This local persistence wrapper is not served as clone-readiness evidence. PullReady carries SignedSpoolOwnerGenesis; after TOFU-pinning it, the client constructs this keyring from the verified root and state-tree transition entries. Loading it recomputes every id/hash and verifies the full chain; unknown versions, gaps, duplicate sequences, forks, owner-id mismatch, or capabilities for another spool fail closed. Portable proof of one exact owner-key state, including historical states used by resource transfers. Several states of the same owner may appear.
- Owner
KeyBinding - Self-asserted attachment of a root key to the stable owner UUID.
stable_owner_uuidis exactly 16 bytes and never changes.challenge_nonceis exactly 32 bytes, single-use, and scoped by the service to the authenticated principal and UUID. binding_epoch begins at one and increases monotonically. - Owner
KeyTransition - Owner
Registration - Owner
Root - Owner
State - Account authority and resource ownership are separate. A root can be established before a spool exists. A spool’s genesis/transfer chain refers to that authority without changing the resource identity.
- Owner
Transition Record - A persisted proposal is distinct from an accepted owner state. Its original signatures remain independently verifiable; version governs complete/veto.
- Owner
Transition Response - Submission durably records a proposal. A later distinct operation completes it after its signed veto window; retrying submission never commits it.
- Ownership
Event - Pack
Chunk - Pack
Extent - Page
Info - Page
Request - Pairing
Event - Pairing
Initiation Binding - Pairing
Record - Paper
Code KdfMaterial - Paper
Code Unlock - Passkey
Authority - Current owner authorization for a passkey to attach temporary Ed25519 mint keys. This certifies key lineage, not operations: Biscuit attenuation, resource audience and current revocation remain mandatory. It confers no independent owner/root-establishment authority. Canonical fields follow tag order using fixed-width/length-prefixed encoding; domain “heddle-passkey-authority-v1”.
- Passkey
Mint Delegation - Passkey
Mint Grant - Account-free request for one passkey to authorize a temporary Ed25519 mint key. Canonical v1 fields follow tag order using fixed-width/length-prefixed encoding. Domain: “heddle-passkey-mint-grant-v1”. The WebAuthn challenge is SHA-256(domain || canonical fields). Account and owner fields are deliberately absent and MUST be derived from PasskeyMintDelegation.authority.
- Passkey
Proof - Passkey
Record - Account-private passkey inventory, requested through ObserveIdentity. The certificate is public verification material; no credential private key or reusable assertion is returned. Device registration is a separate lifecycle.
- Passkey
Registration - Password
Challenge Metadata - Only returned for PASSWORD. Every handle without an active password setup (unknown, passkey-only, deleted, or disabled) gets indistinguishable public metadata: salt derived deterministically from a server secret and the canonical handle, with the same costs, KDF/version, and response shape. Challenge IDs/nonces remain fresh. The server binds the account internally, never via a handle-to-UUID value at begin. Creation is throttled; expiry <= 10 minutes.
- Password
Challenge Proof - Proof of the public password verifier only. This message is never accepted by CompleteAuthentication, an owner mutation, or a credential issuer. Ed25519 signs SHA-256(“heddle-password-proof-v1” || canonical transcript): challenge_id[32] || nonce[32] || caller_device_public_key[32] || u32be(operation_id UTF-8 byte length) || operation_id UTF-8 || i64be(expiry Unix seconds). No protobuf is signed. The server’s one-use challenge record binds the current envelope revision; it is returned only with the continuation after successful proof.
- Password
Device Admission - The owner signs this exact admission, independently of the password proof. Ed25519 signs SHA-256(“heddle-password-device-admission-v1” || u32be(format_version) || account_uuid[16] || challenge_id[32] || continuation_id[32] || caller_device_public_key[32] || owner_state_hash[32] || u64be(owner_sequence) || u32be(client_operation_id UTF-8 byte length) || client_operation_id UTF-8).
- Password
Owner Envelope V1 - Encrypted 32-byte Ed25519 owner seed. The server stores and returns these opaque bytes, never a password, KEK, auth seed, or decrypted owner seed. Reject unknown versions/KDFs before use. Discard unknown protobuf fields and persist only the canonical re-encoding of known fields (<= 4096 bytes). AES-GCM AAD is ASCII(“heddle-owner-wrap-aad-v1”) || 0x00 || u32be(version) || account_uuid || owner_public_key || owner_id || u32be(kdf_id) || u32be(memory_kib) || u32be(iterations) || u32be(parallelism) || wrap_salt.
- Password
Owner Setup - Public authentication metadata, stored separately from the encrypted seed. Client input is UTF8(NFC(password)), preserving case and all spaces. Client guidance is 15+ Unicode characters and at most 1024 UTF-8 bytes; the server cannot enforce strength without seeing the password. The independent inputs are UTF8(“heddle-password-auth-v1”) || 0x00 || UTF8(NFC(password)) with auth_salt, and UTF8(“heddle-owner-wrap-v1”) || 0x00 || UTF8(NFC(password)) with wrap_salt. Both use the recorded Argon2id costs and 32-byte output. Only the Ed25519 public key derived from auth_seed crosses the network. Discard unknown fields, including nested envelope fields, and persist only the canonical re-encoding of known fields (<= 4608 bytes). The verifier and owner keys MUST be canonical, decompressible, and non-small-order. Ed25519 signatures use strict verification: canonical R and S, non-small-order points, and the standard group equation. Rust uses verify_strict; WebCrypto callers MUST precheck these conditions before its verify operation.
- Password
Owner Setup Authorization - Owner authorization for changing the password envelope. The owner signs SHA-256(“heddle-password-owner-setup-change-v1” || u32be(format_version) || u32be(action) || account_uuid[16] || owner_state_hash[32] || u64be(expected_revision) || setup_sha256[32] || u32be(client_operation_id UTF-8 byte length) || client_operation_id || i64be(expires_at Unix seconds)). expires_at has zero nanos and is future, with a bounded lifetime of at most 10 minutes from issuance. setup_sha256 is SHA-256 of the fixed-order v1 setup fields (the envelope’s fields in tag order, followed by auth_salt, verifier key, auth costs, auth_kdf_id and format_version; the possession signature is excluded), with byte fields raw and integers big-endian. DELETE uses 32 zero bytes. The current active account UUID, owner public key and owner ID MUST equal the setup envelope fields. Both actions CAS the account-lifetime revision. A successful PUT or DELETE atomically increments it and invalidates every outstanding password challenge and continuation. DELETE retains a tombstone revision; re-setup CASes against that value. Revision 0 is allowed only when no password setup has ever existed for this account; no revision is reused.
- Password
Unlock Completion - Password
Unlock Continuation - One-use delivery receipt, never a session, bearer, owner authorization or Biscuit. The continuation is bound to the challenge, revision, account and caller device, expires with the challenge, and is consumed at completion.
- Pinned
Source Target Revision - Prepare
Account Claim Request - Device-local consent for claiming an agent-rooted human account. Browser possession and the explicit claim authorization are both required. Weft independently verifies the registration; the device never submits it.
- Prepare
Account Claim Response - Presence
Event - Presence session fan-out events for Track B
/presence/ws. - Principal
Record - Principal
Ref - Promote
Spool Request - Move a personal-root child to the account’s root-level address at its current slug. UUID, genesis, descendants, and direct grants survive. Bound by the destination ancestry’s effective max_audience: refuse promotion that would place a too-wide child under a tighter destination. Birth-parent lock does not follow the promoted spool.
- Proposed
Human Action - Prove
Password Unlock Request - Provenance
Read - Provenance
Result - Provider
Assembly Record - One record in output-pack order. Provider bytes must occupy an exact tiled physical range; inline bytes arrive as bounded ProviderInlineChunk frames. In either case the client verifies the encoded bytes and decoded object.
- Provider
Challenge - Provider
Connection - Provider
Consent - Provider
Dial Route - Authenticated transport hints only. The connected Iroh peer must still match provider.public_key; a URL is never a source of authority.
- Provider
Extent - Provider
Extent Event - Provider
Inline Chunk - Provider
Inline Source - Provider
Offer - Provider
Offer Extent - Capability-free candidate layout. It is not a serving grant. The client consents to its exact challenge before the issuer publishes ticket-bearing ProviderPlan; both phases use the same canonical layout commitments.
- Provider
Pack Location - Trusted issuer-to-provider control-plane registration. Never sent over the client Fetch stream. object_key names a private provider bucket object and must not appear in a client-visible ProviderPlan or ReadProviderExtent.
- Provider
Physical Range - A physical R2 range exactly tiled by independently hashed encoded records. record_set_commitment is a metadata commitment over pack identity, offset, length and ordered encoded record digests; it is not a hash of range bytes.
- Provider
Plan - Provider
Plan Challenge - An unsigned challenge carried over an already authenticated Fetch stream. Only the client’s exact-plan consent is signed. Both digests and the selected Thread/revision bind all tickets and virtual-pack placement.
- Provider
Plan Registration - Provider
Plan Registration Receipt - Provider
Range Chunk - Provider
Range Source - Provider
Read Ticket - The provider verifies this typed ticket against the published canonical extent set and the attenuated caller capability. A ticket alone grants no access; the opening’s native request proof binds the bearer key, the authenticated Iroh client peer matches client, and the receiver’s endpoint matches provider. Root rotation and expiry are independently checked.
- Provider
Repository - Provider
Result - Provision
Account Request - Invite-gated creation of an unclaimed human account. The independent root
slot stays empty. The agent proves its own key over this exact request using
principal:device-key:
; a human bearer cannot replace that proof. Existing key-bound accounts may be reused without an invitation. Reusing an operation ID with different bytes is rejected. - Provision
Account Response - Public
Handle Record - Public directory metadata contains no stable subject/account identifiers. ResolveResources supplies those only within an authorized resource scope.
- Public
Owner - A display label for a publicly visible catalog row. Neither field grants access or supplies an owner verification key.
- Public
Principal Summary - Public presentation only; never carries credential, account settings or rights.
- Publication
Receipt - Publish
Content Client Frame - Publish
Content Finish - Publish
Content Open - Bulk content availability for an already admitted Thread capture. Metadata replication owns causal heads; uploading bytes cannot select or replace one. The opening PoP binds the exact Thread/revision, policy, complete pack/index addresses and lengths, operation identity, and any resume checkpoint.
- Publish
Content Server Frame - Purge
Operation Signing Body - Protobuf serialization is never signed. canonical_purge_operation_v2 is: u32_be(format_version), raw 16-byte spool_uuid, blob_hash as a u32-length- prefixed string, raw 32-byte payload_sha256, raw 32-byte leaf_capability_id. The leaf subject signs SHA-256(“heddle-purge-operation-v2” || canonical_body). The verifier binds this body to the actual spool, payload and direct PURGE grant. Moving the RPC package does not change this durable signing format.
- Purge
Sidecar Identity - PutApproval
Group Request - PutContext
Request - PutDelegation
Request - PutGrant
Request - PutPassword
Owner Setup Request - PutRecovery
Policy Request - PutReview
Policy Request - PutRun
Policy Request - Read
Artifact Request - Read
Budget - Read
Content Request - Read
Provider Extent Request - Record
Evidence Request - Record
Interaction Request - Record
Ref - Record
Review Request - Record
Signature - Recover
Checkout Request - Recovery
Argon2id Params - Recovery
Attempt - Recovery
Guardian - Recovery
Policy - The owner precommits to a threshold over distinct dedicated guardian keys. Product policy defaults to threshold >= 2 and a device-independent co-factor whenever Weft is a guardian. A 1-of-1 Weft policy is custodial and is allowed only after the client obtains the separately reviewed explicit confirmation.
- Redeem
Invitation Request - Redeem
Signup Invitation Request - A held shareable invitation code selects the admission directly; no lookup RPC, account bearer or device root is needed before choosing a passkey.
- Redeem
Signup Invitation Response - Refresh
Checkout Request - Register
Root Attachment Request - Registration
Challenge - Registration
Recovery Policy - Release
Checkout Writer Request - Remote
Link Record - Removal
- Remove
Spool Mount Request - Rename
Thread Request - Renew
Ephemeral Session Request - Renews a short-TTL ephemeral (declined-enrollment) session in place. The renewal is proven by the caller’s existing ephemeral bearer plus a request PoP signed by the ephemeral key (CallContext.request_proof), so the body carries no session ref: the renewed session is exactly the caller’s own.
- Renew
Ephemeral Session Response - Reopen
Discussion Request - Replicate
Thread Request - Replicate
Thread Response - Replication
Have - Replication
Need - Replication
Open - Replication
Operations - Replication
Ready - Replication
Receipt - Replication
Rejection - Request
Held Handle Request - Request
Held Handle Response - Requirement
- Resolve
Checkout Request - Resolve
Discussion Request - Resolve
Handles Request - Resolve
Handles Response - Resolve
Invitation Request - Public capability preview. The invitation ID alone reveals nothing; the redemption secret is passed in the request body and never placed in a URL path or query. No recipient email or inviter identity is disclosed.
- Resolve
Ownership Conflict Request - The original local owner chooses the winning account; that account’s currently authorized owner or delegate accepts. Neither arrival order nor a claimant’s signature alone adjudicates the conflict. Never implicit in upload/enrollment.
- Resolve
Resources Request - Resolve
Resources Response - Resolve
Signup Invitation Request - Resource
Ownership Transfer - Complete client-authored transfer. Missing either signature fails closed.
- Resource
Resolution - Resource
Selector - Account names and paths resolve to stable resources once. They never become authorization roots or replace the stable IDs in subsequent commands.
- Resource
Transfer Acceptance - Resource
Transfer Audit Record - Append-only result committed atomically with the resource-to-owner re-anchor. audit_record_hash is SHA-256(“heddle-resource-transfer-audit-v1” || the canonical transfer, commit time, and previous audit hash).
- Resource
Transfer Handoff - Canonical source offer for an atomic resource ownership re-anchor. canonical_resource_transfer_handoff_v1 encodes fields 1 through 8 in field order using fixed-width big-endian integers and length-prefixed byte strings. UUIDs are exactly 16 bytes, state hashes and nonce are exactly 32 bytes.
- Resume
Subscription Request - Retry
Import Source Request - Retry a failed native source fetch/adoption into its original Thread. The original operation remains immutable; this command creates a new operation and never creates a second Spool or Thread genesis.
- Review
Comparison - Exact comparison resolved within a review-section snapshot. A client submits these source/base/policy bytes when recording a decision; a Thread’s genesis base and an arbitrary source head are not substitutes for this binding.
- Review
Coverage - Review
Decision - Review
Policy Record - Review
Record - The observed decision and the exact portable signed control that authored it.
- Review
Symbol Anchor - Review
Symbols - Revise
Intent Request - Revise
Spool Request - Compare and replace display name and complete settings atomically. The stable UUID, parent, and immutable owner genesis are unchanged. Owner signature is not a prerequisite. The mere existence of a signed-policy tip does not block this RPC (independent CAS from expected_head). settings.audience / default_state_audience are bounded by the standing inherited max_audience (this spool and ancestors). Exceeding it is PERMISSION_DENIED.
- Revision
Ref - Revoke
Delegation Request - Revoke
Device Request - Revoke
Grant Request - Revoke
Invitation Request - Revoke
Provider Connection Request - Revoke
Session Request - Root
Attachment - User-root proof is portable. Account association records Weft’s acceptance of an already user-authorized key; it is not the source of that key’s authority.
- Root
Attachment Binding - Portable binding of a proved delegated key to its Iroh endpoint. Authority remains the Biscuit’s complete attenuation chain, not this locator binding. SignedRecord format heddle.root-attachment.v2 carries canonical bytes signed by both endpoint and subject (one signature when the keys are equal). The shared verifier requires a locally trusted root, verifies the Biscuit’s effective proof key and limits, then verifies digest, time and endpoint.
- RunArtifact
- RunEvent
- RunPermission
- RunPolicy
- RunRecord
- Search
Domain Status - Per-domain readiness is independent of result count and hidden matches. An unavailable index is not represented as an empty, complete result set.
- Search
Event - Search
Hit - Search
Request - Section
Replacement - Section
Status - Semantic
Index Artifact - Self-contained derived index, readable in one bounded artifact stream. Nodes are unique and sorted by hash; root_hash is 32 bytes and must name an included root. All derived root/tree/file nodes are included and verified. Opaque file entries may identify source commitments, but their raw source bytes are never included. Parsed/opaque counts describe this exact source.
- Semantic
Index Object - One existing Heddle semantic root/file/directory object. The canonical bytes use the versioned Heddle semantic index codec. The 32-byte hash uses Heddle’s Blob identity: BLAKE3(UTF8(“blob”) || uint64_le(canonical.length) || 0x00 || canonical), matching Blob::hash(). Hashing canonical alone is incorrect. This object grants no right to fetch other CAS objects.
- Session
Record - SetAttention
State Request - SetBookmark
Request - SetNotification
Preferences Request - SetRemote
Link Request - SetSpool
Mount Request - SetSupport
Access Request - SetThread
Audience Request - SetThread
Retention Request - SetThread
Sharing Request - Sharing
Destination - Sidecar
Authorization - Portable authorization for an exact purge, independently of its transport.
- Sign
Account Claim Request - Sign
Account Claim Response - Signed
Mint Root Attachment - Portable owner -> passkey -> temporary mint-key authorization. This v2 shape is the only SignedMintRootAttachment accepted for passkey sign-in.
- Signed
Owner Capability - Signed
Owner KeyTransition - Authorizations sign canonical_owner_key_transition_v1(transition).
- Signed
Owner Mint Root Attachment - Owner-signed account-bound attachment retained for registration of a durable independent mint root. Passkey authentication never accepts this shape: its account-free grant and owner-certified passkey chain use SignedMintRootAttachment below.
- Signed
Owner Root - Signed
Passkey Authority - Signed
Password Device Admission - Signed
Password Owner Setup Authorization - Signed
Policy Body - Signed
Policy Head - CAS predecessor. Independent of ReviseSpool.expected_version. Zero hash + sequence 0 = genesis.
- Signed
Policy Merge Rule - Signed
Record - A durable, versioned record. Its format defines canonical bytes, domain, signature algorithm, bounds and verifier. Generic protobuf serialization is never the signing input. Unknown critical formats fail closed.
- Signed
Resource Transfer Handoff - Signed
Spool Owner Genesis - Self-signed genesis evidence. owner_signature.signer_key_id MUST identify genesis.owner_public_key, and that key signs the exact 32-byte digest:
- Signed
Spool Policy - Offline-verifiable, owner-gated payload. NOT a copy of SpoolSettings. Substantive content: grow-only revocations + max_audience ceiling.
- Signed
Spool Policy Record - Signup
Invitation - Signup
Invitation Resolution - Signup
Reservation - Source
Anchor - Source
Conflict Candidate - Source
Conflict Set - A bounded set of immutable source alternatives observed at one checkout version. Candidate IDs are opaque and only meaningful within this version.
- Source
Location - Exact current coordinates, never an authoring input or a replacement for the original evidence in SourceAnchor. No implicit tracking from these fields.
- Source
Operation Frontier - Source
Target Reference - Shared by primary anchors and annotation references. This is a reference, never a grant to read the target’s source or its owning Thread.
- Source
Target Resolution - Source
Target Resolution Event - Shared map updates for anchors and tags. Snapshot/Upsert frames carry upsert; Remove frames carry remove. Deduplicate by key within a checkpoint batch. Maps clear with Thread collaboration / Spool context section replacement and replacement snapshots. Remove the entry when its last referrer leaves the observed window. Neither missing targets nor these events grant source access.
- Source
Target Resolution Key - Stable within an endpoint observation. Only a viewed_thread binding requires viewed_thread here; named and pinned bindings MUST omit it. The selected revision is a value, so capture moves one shared entry, not every referrer.
- Source
Target View - Exact view selection for a Thread’s inherited target bindings. This selects resolution only; it grants no source access and does not select more records.
- Spool
Address - Observed address of a stable Spool identity. Renames change the address, never the UUID. An address is presentation/routing metadata, not authority.
- Spool
Capability Grant - Spool
Creation Proof - Spool
Creation Statement - A creator’s statement of exact intended creation. created_at is NOT an admission timestamp. Only actual current admission or independently retained accepted evidence establishes whether this creation was permitted then. Canonical v1 fields follow tag order; domain “heddle-spool-creation-v1”.
- Spool
Event - Spool
Mount - Spool
Mutation Response - Committed overview and independently verifiable owner history seed the caller’s view directly. The receipt is not a trust root or a TOFU pin.
- Spool
Overview - Spool
Owner Genesis - Immutable owner-key binding created with a spool.
spool_uuidis the raw 16-byte UUIDv7 that is also the spool id.owner_public_keyis the owner authority key at creation; no registry key or nonce participates. - Spool
Pages - Spool
Ref - Spool
Selector - Spool
Settings - Fresh bootstrap permits child creation and has no implicit approval mandate. Explicit review policies still apply. A revision supplies the complete record; its settings participate in the observed review policy version.
- Stack
Landing - Each source is the exact revision supplied by the caller. For every distinct target, expected_target is compared once against the initial transaction snapshot. Ordered members then integrate into that target’s evolving frontier.
- Start
Analysis Request - Start
Thread Request - State
Read - Exact immutable source summary. Authored sidecars (including risk signals, conflict resolutions and semantic attachment attribution) are not source objects: use audience-checked Thread, checkout and Analysis projections. The selection emits one StateSummary followed by selection_complete.
- Store
Provider Credential Request - Stream
Checkpoint - Stream
Complete - Stream
Data - Stream
Frame - Stream
Heartbeat - Stream
Open - Stream
Reset - Submit
Owner Capability Request - Submit
Owner Transition Request - Submit
Recovery Proof Request - Submit
Recovery Proof Response - Submit
Signed Policy Request - Owner-signed spool policy submit. Not a prerequisite of ReviseSpool. request.spool MUST equal record.body.spool_uuid; mismatch fails closed. Proposed max_audience, if present and specified, MUST be <= the ancestors’ effective ceiling (min over ancestors only). Retry by client_operation_id. The biscuit RESOURCE_OWNER role is necessary but not sufficient: the verifier checks the owner signature against the server-derived current owner OwnerState. Receipt binds SignedPolicyHead (Decision 8).
- Submit
Signed Policy Response - Support
Access Record - Synchronize
Remote Request - Thread
Audience Policy - Thread
Control Authority - Original author evidence bound into each signed Thread metadata operation. Supplied history never establishes trust: receivers verify against separately admitted current account authority at first durable admission. Canonical protobuf encoding is mandatory and the entire envelope is bounded to 64 KiB.
- Thread
Event - One typed stream composes a Thread’s decision context. Common frame controls have no payload. Every data frame carries exactly one payload; snapshots and delta batches become visible only at their checkpoint. SectionReplacement.section and SectionStatus.section use these exact keys: overview (overview); captures (capture); review (comparison, review, diff); evidence (evidence, check_acknowledgement); collaboration (discussion, turn, context, source_target); analysis (analysis); checkouts (checkout); timeline (timeline_event, run, operation); sharing (sharing, publication). Replacement clears only that section’s committed collection. Unknown section semantics require a fresh supported view, never silent loss.
- Thread
Genesis Record - Carries original ownership proof with the immutable creator-signed identity. The receiver independently verifies it; transport credentials never select the owning account or enroll an otherwise-untrusted account root.
- Thread
Id - Thread
Intent - Thread
Invitee - Thread
List Event - Thread
Metadata Conflict - Thread
Mutation Response - Thread
Name Selector - Thread
Overview - Thread
Ownership - Thread
Ownership Conflict - Thread
Pages - Independent section windows share one observation’s total read budget. Missing windows select bounded defaults only for requested sections.
- Thread
Property Frontier - Thread
Query - Thread
Ref - Thread
Relationship - Thread
Retention Policy - Thread
Sharing Policy - Timeline
Record - Transfer
Checkpoint - Transfer
Object - Transfer
Ownership Request - Transfer
Ready - Transfer
Selection - Transfer
Sidecar - Tree
Read - Unsubscribe
Notifications Request - Public, single-purpose disabling action. The opaque capability determines the recipient and exact allowed selectors; no account credential is required. Each requested rule must select an authorized channel and DISABLED delivery.
- Update
Subscription Request - Verified
Email Reservation - Verify
Evidence Request - Verify
Evidence Response - Veto
Owner Transition Request - Veto
Recovery Request - Weft
Custody Recovery Policy Selection - The only supported custodial recovery shape is exactly one WEFT guardian with threshold one. It is never inferred from an omitted selection.
- Weft
Custody Warning Consent - Versioned evidence that the user saw and accepted the exact 1-of-1 Weft custody warning. warning_sha256 is SHA-256 of the reviewed UTF-8 warning text for warning_version; unknown versions and digests fail closed.
- Workspace
Event - Workspace
Pages
Enums§
- Account
Deletion Outcome - Analysis
Kind - Audience
- Existence/history audience for a spool. Numeric tags match v1 Visibility (PRIVATE=1, INTERNAL/MEMBERS=2, PUBLIC=3). Do not add AUDIENCE_INTERNAL.
- Authorization
KeyAlgorithm - Behavior
Correspondence Kind - Behavior
Limitation - Behavior
Match Reason - Behavior
Provenance - Behavior
Support - Billing
Interval - Capability
Principal Kind - Catalog
Sort - Public resource discovery never includes private grants, devices or account attention. Exact public content still uses the ordinary resource read APIs.
- Clone
Owner PinKind - Coverage
- Credential
Kind - Credential
Method - Explicit ceremony selection; omitted or unsupported methods are rejected. Password unlocks a client-held owner key; OAuth retains its own ceremony. Neither a password verifier signature nor an OAuth proof is owner authority.
- Endpoint
Kind - Handle
Kind - Hold
Lifecycle - Delegated HOLD-verdict lifecycle on SpoolSettings. Not abandoned_thread_retention. v1 VersionedHoldLifecycle was chain-inherited and offline-citable; moving HOLD here drops that citation. UNSPECIFIED inherits; the built-in root default is EXPLICIT_SUPERSESSION.
- OAuth
Provider - Observation
Mode - Shared observation protocol. Each RPC has a typed event payload alongside StreamFrame. Only a data frame carries a payload. See docs/alpha-v2/streams.md. A logical RPC occupies one reliable, ordered Iroh stream; this contract does not turn protobuf frames into unreliable UDP datagrams.
- Owner
KeyBinding Kind - Owner
KeyTransition Kind - Recovery
Guardian Kind - Recovery-key provenance is part of the signed policy. A verifier can distinguish paper, social, and Weft guardians when counting signatures.
- Requirement
Kind - Resource
Role - Review
Readiness - Rooting
Tier - Account onboarding state, never a substitute for a verified capability or owner-root binding. Promotions are explicit; a credential’s attenuation must survive promotion of its account. AGENT_ROOTED denotes an unclaimed human account with an empty independent-root slot, not an account owned by an agent.
- Search
Domain - Search
Match Kind - How this match was established; score is only comparable within this query.
- Search
Source History - Which accepted source revisions participate in content and symbol search.
- Seat
Pricing Mode - Shared
Facet - Signed
Policy Merge Semantics - Spool
Capability Action - Spool
Section - Stream
Data Kind - Stream
Reset Reason - Subscription
Status - Provider IDs, API credentials and webhook secrets never appear in this contract. Weft resolves the authenticated account and checks the credential’s effective delegated billing authority for every read and mutation.
- Thread
Lifecycle - Thread
Property - Thread
Section - Timeline
Start - Selects where a single run’s timeline observation begins. This does not change the default oldest-first collection pagination.
- User
Verification