Expand description
Frozen Thread-oriented contract; endpoint support is negotiated.
Modules§
- analysis_
event - Nested message and enum types in
AnalysisEvent. - analysis_
finding - Nested message and enum types in
AnalysisFinding. - annotation_
property_ predicate - Nested message and enum types in
AnnotationPropertyPredicate. - annotation_
tag - Nested message and enum types in
AnnotationTag. - annotation_
tag_ predicate - Nested message and enum types in
AnnotationTagPredicate. - annotation_
value - Nested message and enum types in
AnnotationValue. - artifact_
event - Nested message and enum types in
ArtifactEvent. - attention_
event - Nested message and enum types in
AttentionEvent. - attention_
item - Nested message and enum types in
AttentionItem. - begin_
pairing_ request - Nested message and enum types in
BeginPairingRequest. - begin_
registration_ request - Nested message and enum types in
BeginRegistrationRequest. - behavior_
assignment - Nested message and enum types in
BehaviorAssignment. - behavior_
branch - Nested message and enum types in
BehaviorBranch. - billing_
event - Nested message and enum types in
BillingEvent. - blob_
read - Nested message and enum types in
BlobRead. - bookmark_
ref - Nested message and enum types in
BookmarkRef. - catalog_
event - Nested message and enum types in
CatalogEvent. - check_
evidence_ summary - Nested message and enum types in
CheckEvidenceSummary. - checkout_
event - Nested message and enum types in
CheckoutEvent. - collaboration_
anchor - Nested message and enum types in
CollaborationAnchor. - collaboration_
event - Nested message and enum types in
CollaborationEvent. - complete_
authentication_ request - Nested message and enum types in
CompleteAuthenticationRequest. - complete_
pairing_ request - Nested message and enum types in
CompletePairingRequest. - complete_
registration_ request - Nested message and enum types in
CompleteRegistrationRequest. - content_
event - Nested message and enum types in
ContentEvent. - content_
read - Nested message and enum types in
ContentRead. - content_
tree_ entry - Nested message and enum types in
ContentTreeEntry. - control_
run_ request - Nested message and enum types in
ControlRunRequest. - create_
spool_ request - Nested message and enum types in
CreateSpoolRequest. - credential_
result - Nested message and enum types in
CredentialResult. - delegation_
record - Nested message and enum types in
DelegationRecord. - discussion_
record - Nested message and enum types in
DiscussionRecord. - entity_
ref - Nested message and enum types in
EntityRef. - fetch_
client_ frame - Nested message and enum types in
FetchClientFrame. - fetch_
open - Nested message and enum types in
FetchOpen. - fetch_
server_ frame - Nested message and enum types in
FetchServerFrame. - handle_
resolution - Nested message and enum types in
HandleResolution. - identity_
event - Nested message and enum types in
IdentityEvent. - integration_
event - Nested message and enum types in
IntegrationEvent. - invitation_
resolution - Nested message and enum types in
InvitationResolution. - material_
retention - Nested message and enum types in
MaterialRetention. - mutation_
receipt - Nested message and enum types in
MutationReceipt. - notification_
event - Nested message and enum types in
NotificationEvent. - notification_
rule - Nested message and enum types in
NotificationRule. - o_
auth_ proof - Nested message and enum types in
OAuthProof. - operation_
event - Nested message and enum types in
OperationEvent. - operation_
record - Nested message and enum types in
OperationRecord. - ownership_
event - Nested message and enum types in
OwnershipEvent. - pack_
extent - Nested message and enum types in
PackExtent. - pairing_
event - Nested message and enum types in
PairingEvent. - pairing_
initiation_ binding - Nested message and enum types in
PairingInitiationBinding. - pairing_
record - Nested message and enum types in
PairingRecord. - presence_
event - Nested message and enum types in
PresenceEvent. - provider_
assembly_ record - Nested message and enum types in
ProviderAssemblyRecord. - provider_
dial_ route - Nested message and enum types in
ProviderDialRoute. - provider_
extent_ event - Nested message and enum types in
ProviderExtentEvent. - publication_
receipt - Nested message and enum types in
PublicationReceipt. - publish_
content_ client_ frame - Nested message and enum types in
PublishContentClientFrame. - publish_
content_ server_ frame - Nested message and enum types in
PublishContentServerFrame. - record_
interaction_ request - Nested message and enum types in
RecordInteractionRequest. - registration_
recovery_ policy - Nested message and enum types in
RegistrationRecoveryPolicy. - remote_
link_ record - Nested message and enum types in
RemoteLinkRecord. - replicate_
thread_ request - Nested message and enum types in
ReplicateThreadRequest. - replicate_
thread_ response - Nested message and enum types in
ReplicateThreadResponse. - resolve_
discussion_ request - Nested message and enum types in
ResolveDiscussionRequest. - resource_
selector - Nested message and enum types in
ResourceSelector. - review_
coverage - Nested message and enum types in
ReviewCoverage. - review_
decision - Nested message and enum types in
ReviewDecision. - revision_
ref - Nested message and enum types in
RevisionRef. - run_
event - Nested message and enum types in
RunEvent. - search_
event - Nested message and enum types in
SearchEvent. - search_
request - Nested message and enum types in
SearchRequest. - signup_
invitation_ resolution - Nested message and enum types in
SignupInvitationResolution. - source_
target_ reference - Nested message and enum types in
SourceTargetReference. - source_
target_ resolution - Nested message and enum types in
SourceTargetResolution. - source_
target_ resolution_ event - Nested message and enum types in
SourceTargetResolutionEvent. - spool_
creation_ proof - Nested message and enum types in
SpoolCreationProof. - spool_
event - Nested message and enum types in
SpoolEvent. - stream_
frame - Nested message and enum types in
StreamFrame. - submit_
owner_ transition_ request - Nested message and enum types in
SubmitOwnerTransitionRequest. - submit_
recovery_ proof_ request - Nested message and enum types in
SubmitRecoveryProofRequest. - submit_
recovery_ proof_ response - Nested message and enum types in
SubmitRecoveryProofResponse. - thread_
audience_ policy - Nested message and enum types in
ThreadAudiencePolicy. - thread_
control_ authority - Nested message and enum types in
ThreadControlAuthority. - thread_
event - Nested message and enum types in
ThreadEvent. - thread_
list_ event - Nested message and enum types in
ThreadListEvent. - thread_
ownership - Nested message and enum types in
ThreadOwnership. - thread_
query - Nested message and enum types in
ThreadQuery. - thread_
relationship - Nested message and enum types in
ThreadRelationship. - timeline_
admission_ acceptance - Nested message and enum types in
TimelineAdmissionAcceptance. - transfer_
sidecar - Nested message and enum types in
TransferSidecar. - upload_
scrubbed_ timeline_ response - Nested message and enum types in
UploadScrubbedTimelineResponse. - veto_
recovery_ request - Nested message and enum types in
VetoRecoveryRequest. - workspace_
event - Nested message and enum types in
WorkspaceEvent.
Structs§
- Acknowledge
Check Request - Action
Availability - Agent
Ref - Stable delegated agent identity, scoped to its owning account. Neither a display name nor a rotating signing key is an agent’s resource identity.
- Analysis
Artifact - Immutable derived analysis output. Stored under an opaque Thread-scoped artifact identity; this is never an authorization wrapper for source bytes. Readers decode one canonical message, not concatenated stream frames. The producer rejects outputs larger than its advertised artifact byte budget.
- Analysis
Event - Analysis
Finding - Analysis
Record - Annotation
Decimal - Structured context metadata. References describe a target; they grant no access to it and never change the annotation’s primary anchor or audience.
- Annotation
Property - Annotation
Property Predicate - Annotation
Query - Annotation
Source Reference - Annotation
Symbol Tag - Annotation
Tag - Annotation
TagPredicate - Annotation
Value - Anonymous
Session Response - Append
Discussion Request - Applied
- Approval
Group Record - Approve
Pairing Request - Artifact
Event - Attach
Provider Installation Request - Attach a GitHub App installation that became available after OAuth consent. The hosted service validates the exact installation against the caller’s stored provider credential before updating the connection.
- Attention
Event - Attention
Item - Authentication
Challenge - Authentication
Response - Authorization
Signature - Authorization
Verification Key - Begin
Authentication Request - Begin
Checkout Request - Begin
Email Verification Request - Begin
Pairing Request - Begin
Pairing Response - Begin
Provider Connection Request - Begin
Recovery Request - Begin
Recovery Response - Begin
Registration Request - Behavior
Analysis Coverage - Behavior
Assignment - Behavior
Binding - Behavior
Branch - Behavior
Byte Span - Behavior
Change - A self-contained structural map. Typed containment (assignment.value_id, conditional.predicate_id), selection (branches), binding and correspondence are distinct. This version emits no inferred consequences or test approval; resolved call/reference graph edges remain independent evidence and cannot establish execution order or effects. All referenced IDs must occur here.
- Behavior
Change Removal - Behavior
Conditional - Behavior
Correspondence - Behavior
Dependencies - Behavior
Expression - Behavior
Operation - Behavior
Scope - Each entry describes only this analyzer’s supported pattern, not all behavior in a file or file group. Empty supported scope means no supported changes; omitted scope, partial analysis and interrupted streams are different states.
- Behavior
Source - Source navigation is pinned to bytes, never just a semantic digest. Byte offsets are zero-based, half-open UTF-8 byte ranges. No inferred locations.
- Behavior
Versions - Billing
Event - Billing
Plan - Billing
Record - Billing
Redirect Response - Billing
Seat Pricing - Billing
Seat Tier - Blob
Chunk - Blob
Read - Blocked
- Bookmark
Mutation Response - Bookmark
Record - Bookmark
Ref - Caller-private preference identity; changing it never changes its target.
- Bootstrap
Ownership Request - Browser
Pairing Approval Binding - Browser
Pairing Completion Binding - SignedRecord format heddle.browser-pairing-completion.v1. The current subject key signs domain || deterministic protobuf bytes plus a fresh exact RPC proof.
- Browser
Pairing Receiver - Provisional two-key possession, before an approving account is known. SignedRecord format heddle.pairing-initiation.v2; each actual receiver key signs domain || protobuf bytes in ascending tag order, omitting scalar defaults. Oneof presence is preserved. The host and operation prevent reuse. Credential-only receiver. Its subject key is not an Iroh endpoint.
- Cancel
Operation Request - Cancel
Subscription Request - Capability
Principal - Capture
Checkout Request - Capture
Summary - Catalog
Activity Summary - Counts of public activity on one catalog Spool. A server deriving these from rollups may serve eventually consistent values; they are display hints, not authorization or a transactional snapshot of underlying Threads/changes.
- Catalog
Event - Causal
Frontier - A causal frontier is portable within its exact Thread/facet/format. It is never an Observe cursor or a bulk-transfer checkpoint. Heads are paged using the negotiated max_items; repeated Have frames contribute to the same round.
- Change
Thread Lifecycle Request - Check
Acknowledgement Record - Immutable review progress for one accepted check result and exact policy. This does not change its outcome, supersede evidence or grant landing approval.
- Check
Evidence Summary - Derived presentation of canonical signed evidence. The receiving endpoint verifies original authority independently; a reported pass is not itself cryptographic proof that an external process ran correctly.
- Checkout
Event - Checkout
Mutation Response - Checkout
Overview - Checkout
Ref - Checkout
Writer Lease - The same physical-checkout lease is enforced by CLI and device RPCs. Possessing its token never grants authority: each mutation also authenticates the owner session, verifies current capability, and compares source/version.
- Claim
Checkout Writer Request - Claim
Checkout Writer Response - Claim
Handle Request - Claim
Handle Response - Claim
Thread Ownership Request - The owner and accepting account publisher co-sign one exact canonical claim. Upload and device enrollment never invoke this transition implicitly.
- Claim
Thread Ownership Response - Client
Owned Credential - Clone
Authorization Keyring - Clone
Owner Pin - Local provenance chosen and persisted by the client. There is no UUID-to-key migration or legacy TOFU arm: all accounts start owner-anchored.
- Collaboration
Anchor - Collaboration
Event - Complete
Authentication Request - Complete
Email Verification Request - Complete
Email Verification Response - Complete
Owner Transition Request - Complete
Pairing Request - Complete
Provider Connection Request - Complete
Recovery Request - Complete
Registration Request - Content
Event - Content
File - Content
Read - Content
Spool Link - Content
Tree Entry - Context
Draft - Write input. Actor attribution is carried by the signed canonical operation; coverage and current-view versions are server projections, never client input.
- Context
Record - Control
RunRequest - Create
Anonymous Session Request - Anonymous continuity has no human account and no independent owner root. The endpoint retains its existing anti-abuse, expiry and rotation checks.
- Create
Billing Portal Request - Create
Invitation Request - Create
Invitation Response - Create
Signup Invitation Request - Create
Signup Invitation Response - Create
Spool Request - Credential
Inspection - Credential
Result - Returned only by a successful credential ceremony, never by an observation. Keyed clients retain their own minting authority. Registration attaches their proved key to an account/session; it does not mint a bearer or confer an independent human root on an agent. Other keyless ceremonies can return an issued bearer. Password completion MUST return client_owned, never issued.
- Current
Credential Record - Metadata for the exact credential authenticating this observation. This is not issuance, and neither account tier nor account role upgrades its rights.
- Decide
RunPermission Request - Delegation
Credential Response - Delegation
Record - Delete
Account Request - Irreversibly deletes the caller’s account. The authenticating credential MUST be the direct account owner’s proof-bearing credential: agent, service, delegated, derived and attenuated credentials are rejected even if they otherwise carry caller-bound account authority. confirmation_handle MUST exactly equal the account’s current handle. Reusing client_operation_id returns the original outcome without deleting or canceling anything twice.
- Delete
Account Response - Delete
Approval Group Request - Delete
Password Owner Setup Request - Delete
Review Policy Request - Delete
Spool Request - Describe
Endpoint Request - Describe
Endpoint Response - Device
Identity - Diff
Read - Discussion
Record - Discussion
Turn - Email
Verification Challenge - Only the endpoint’s authenticated, independently rooted signup-mailer service account may begin delivery. Its bearer is the possession factor.
- Endpoint
Ref - Entitlement
Record - Entity
Ref - Evidence
Record - Evidence
Verification - Expected
Version - Fetch
Client Frame - Fetch
Complete - Fetch
Open - Fetch
Server Frame - GetIdentity
Request - Bounded unary identity lookup for one-shot callers. The principal is always returned; callers can opt into metadata for the authenticating credential.
- GetIdentity
Response - Grant
Record - Group
Requirement - Guardian
Recovery Policy Selection - Registration defaults to this guardian M-of-N policy. If OwnerRegistration.recovery is absent, the policy in the signed root is treated as this branch and MUST contain a valid threshold and at least one non-WEFT guardian. Absence never selects Weft custody.
- Handle
Resolution - Harness
Preference - Identity
Event - Import
Source Request - Integration
Event - Introspect
Credential Request - Invitation
Quota - Invitation
Record - Invitation
Resolution - Issue
Delegation Credential Request - Creating/updating a delegation record and issuing a credential are different effects. The caller must prove the active delegation authority; the new key must prove possession. Scope/expiry cannot exceed the accepted delegation.
- Issued
Credential - Land
Checkout Request - Land
Stack Request - Land
Thread Request - Landing
Assessment - List
Spools Request - Grant-reachable unary Spool listing for whoami and admin surfaces.
ObserveWorkspace remains the live composed workspace view; this RPC is the
bounded one-shot catalog of Spools reachable through the caller’s grants.
repos_onlykeeps content-bearing (repository/project) rows. - List
Spools Response - Listed
Spool - Mark
Notifications Read Request - Material
Retention - Materialize
Checkout Request - Member
Record - Mint
Root Attachment - Public association of a credential mint root with one exact owner authority state. This grants no operations: ordinary Biscuit checks remain mandatory. Canonical v1 fields follow tag order using fixed-width/length-prefixed encoding. Domain: “heddle-mint-root-attachment-v1”.
- Money
- Mutation
Receipt - Mutation
Response - Notification
Digest Override - Notification
Event - Notification
Preferences - Notification
Record - Notification
Rule - OAuth
Proof - Object
Address - These are native v2 transfers, not envelopes carrying v1 Push/Pull requests. A signed opening binds exact v2 scope, operation, policy, inventory and resume context. Packs and indexes travel as bounded protobuf chunks under flow control.
- Observe
Analysis Request - Observe
Attention Request - Observe
Billing Request - Observe
Catalog Request - Observe
Checkouts Request - Observe
Collaboration Request - Observe
Identity Request - Observe
Integrations Request - Observe
Notifications Request - Observe
Operations Request - Observe
Options - Observe
Ownership Request - Observe
Pairing Request - Observe
Runs Request - Observe
Spool Request - Observe
Thread Request - Observe
Threads Request - Observe
Workspace Request - Open
Discussion Request - Operation
Event - Operation
Record - Owner
Authorization Bundle - Owner
Capability - V1 canonicalization and signature remain unchanged. For format_version=2, canonical_owner_capability_v2 uses the v1 field order and encodings, but every grant appends one presence byte after action (exactly 0x01) followed by scope fields 1..6: each bytes field is u32be(length)||bytes, and class is u32be. The scope is included both with and without capability_id. The v2 capability_id is SHA-256(“heddle-owner-capability-v2” || canonical body without capability_id); its owner signature is Ed25519 over SHA-256 of that domain followed by the canonical body WITH capability_id. The v1 domain and body never acquire a trailing scope field. Unknown fields fail closed. A v2 chain is direct (parent_capability_id empty), has one signed capability and a single-block subject Biscuit bound to its exact subject key/kind/ID and grant. Its authority block has the v1 owner_subject, owner_capability, owner_validity facts plus exactly one owner_timeline_accept(“<spool_uuid_hex>”, “<path_hex>”, “<principal_uuid_hex>”, “<origin_credential_id_hex>”, “<pop_sha256_hex>”, <class_u32>, “<thread_id_hex>”, “<origin_sha256_hex>”) fact, where path_hex is the v1 u32-length-prefixed canonical path segments as lower-case hex. Reject extra facts, attenuation blocks, duplicate grants and any PURGE fact; this direct exact grant cannot be widened by a later block. The grant selector MUST equal the actual canonical Spool UUID/path and MUST have include_descendants=false. V1 PURGE verifiers reject v2 rather than treating this action as purge or ordinary spool-write authority.
- Owner
History - This local persistence wrapper is not served as clone-readiness evidence. PullReady carries SignedSpoolOwnerGenesis; after TOFU-pinning it, the client constructs this keyring from the verified root and state-tree transition entries. Loading it recomputes every id/hash and verifies the full chain; unknown versions, gaps, duplicate sequences, forks, owner-id mismatch, or capabilities for another spool fail closed. Portable proof of one exact owner-key state, including historical states used by resource transfers. Several states of the same owner may appear.
- Owner
KeyBinding - Self-asserted attachment of a root key to the stable owner UUID.
stable_owner_uuidis exactly 16 bytes and never changes.challenge_nonceis exactly 32 bytes, single-use, and scoped by the service to the authenticated principal and UUID. binding_epoch begins at one and increases monotonically. - Owner
KeyTransition - Owner
Registration - Owner
Root - Owner
State - Account authority and resource ownership are separate. A root can be established before a spool exists. A spool’s genesis/transfer chain refers to that authority without changing the resource identity.
- Owner
Transition Record - A persisted proposal is distinct from an accepted owner state. Its original signatures remain independently verifiable; version governs complete/veto.
- Owner
Transition Response - Submission durably records a proposal. A later distinct operation completes it after its signed veto window; retrying submission never commits it.
- Ownership
Event - Pack
Chunk - Pack
Extent - Page
Info - Page
Request - Pairing
Event - Pairing
Initiation Binding - Pairing
Record - Paper
Code KdfMaterial - Paper
Code Unlock - Passkey
Authority - Current owner authorization for a passkey to attach temporary Ed25519 mint keys. This certifies key lineage, not operations: Biscuit attenuation, resource audience and current revocation remain mandatory. It confers no independent owner/root-establishment authority. Canonical fields follow tag order using fixed-width/length-prefixed encoding; domain “heddle-passkey-authority-v1”.
- Passkey
Mint Delegation - Passkey
Mint Grant - Account-free request for one passkey to authorize a temporary Ed25519 mint key. Canonical v1 fields follow tag order using fixed-width/length-prefixed encoding. Domain: “heddle-passkey-mint-grant-v1”. The WebAuthn challenge is SHA-256(domain || canonical fields). Account and owner fields are deliberately absent and MUST be derived from PasskeyMintDelegation.authority.
- Passkey
Proof - Passkey
Record - Account-private passkey inventory, requested through ObserveIdentity. The certificate is public verification material; no credential private key or reusable assertion is returned. Device registration is a separate lifecycle.
- Passkey
Registration - Password
Challenge Metadata - Only returned for PASSWORD. Every handle without an active password setup (unknown, passkey-only, deleted, or disabled) gets indistinguishable public metadata: salt derived deterministically from a server secret and the canonical handle, with the same costs, KDF/version, and response shape. Challenge IDs/nonces remain fresh. The server binds the account internally, never via a handle-to-UUID value at begin. Creation is throttled; expiry <= 10 minutes.
- Password
Challenge Proof - Proof of the public password verifier only. This message is never accepted by CompleteAuthentication, an owner mutation, or a credential issuer. Ed25519 signs SHA-256(“heddle-password-proof-v1” || canonical transcript): challenge_id[32] || nonce[32] || caller_device_public_key[32] || u32be(operation_id UTF-8 byte length) || operation_id UTF-8 || i64be(expiry Unix seconds). No protobuf is signed. The server’s one-use challenge record binds the current envelope revision; it is returned only with the continuation after successful proof.
- Password
Device Admission - The owner signs this exact admission, independently of the password proof. Ed25519 signs SHA-256(“heddle-password-device-admission-v1” || u32be(format_version) || account_uuid[16] || challenge_id[32] || continuation_id[32] || caller_device_public_key[32] || owner_state_hash[32] || u64be(owner_sequence) || u32be(client_operation_id UTF-8 byte length) || client_operation_id UTF-8).
- Password
Owner Envelope V1 - Encrypted 32-byte Ed25519 owner seed. The server stores and returns these opaque bytes, never a password, KEK, auth seed, or decrypted owner seed. Reject unknown versions/KDFs before use. Discard unknown protobuf fields and persist only the canonical re-encoding of known fields (<= 4096 bytes). AES-GCM AAD is ASCII(“heddle-owner-wrap-aad-v1”) || 0x00 || u32be(version) || account_uuid || owner_public_key || owner_id || u32be(kdf_id) || u32be(memory_kib) || u32be(iterations) || u32be(parallelism) || wrap_salt.
- Password
Owner Setup - Public authentication metadata, stored separately from the encrypted seed. Client input is UTF8(NFC(password)), preserving case and all spaces. Client guidance is 15+ Unicode characters and at most 1024 UTF-8 bytes; the server cannot enforce strength without seeing the password. The independent inputs are UTF8(“heddle-password-auth-v1”) || 0x00 || UTF8(NFC(password)) with auth_salt, and UTF8(“heddle-owner-wrap-v1”) || 0x00 || UTF8(NFC(password)) with wrap_salt. Both use the recorded Argon2id costs and 32-byte output. Only the Ed25519 public key derived from auth_seed crosses the network. Discard unknown fields, including nested envelope fields, and persist only the canonical re-encoding of known fields (<= 4608 bytes). The verifier and owner keys MUST be canonical, decompressible, and non-small-order. Ed25519 signatures use strict verification: canonical R and S, non-small-order points, and the standard group equation. Rust uses verify_strict; WebCrypto callers MUST precheck these conditions before its verify operation.
- Password
Owner Setup Authorization - Owner authorization for changing the password envelope. The owner signs SHA-256(“heddle-password-owner-setup-change-v1” || u32be(format_version) || u32be(action) || account_uuid[16] || owner_state_hash[32] || u64be(expected_revision) || setup_sha256[32] || u32be(client_operation_id UTF-8 byte length) || client_operation_id || i64be(expires_at Unix seconds)). expires_at has zero nanos and is future, with a bounded lifetime of at most 10 minutes from issuance. setup_sha256 is SHA-256 of the fixed-order v1 setup fields (the envelope’s fields in tag order, followed by auth_salt, verifier key, auth costs, auth_kdf_id and format_version; the possession signature is excluded), with byte fields raw and integers big-endian. DELETE uses 32 zero bytes. The current active account UUID, owner public key and owner ID MUST equal the setup envelope fields. Both actions CAS the account-lifetime revision. A successful PUT or DELETE atomically increments it and invalidates every outstanding password challenge and continuation. DELETE retains a tombstone revision; re-setup CASes against that value. Revision 0 is allowed only when no password setup has ever existed for this account; no revision is reused.
- Password
Unlock Completion - Password
Unlock Continuation - One-use delivery receipt, never a session, bearer, owner authorization or Biscuit. The continuation is bound to the challenge, revision, account and caller device, expires with the challenge, and is consumed at completion.
- Pinned
Source Target Revision - Prepare
Account Claim Request - Device-local consent for claiming an agent-rooted human account. Browser possession and the explicit claim authorization are both required. Weft independently verifies the registration; the device never submits it.
- Prepare
Account Claim Response - Presence
Event - Presence session fan-out events for Track B
/presence/ws. - Principal
Record - Principal
Ref - Promote
Spool Request - Move a personal-root child to the account’s root-level address at its current slug. UUID, genesis, descendants, and direct grants survive. Bound by the destination ancestry’s effective max_audience: refuse promotion that would place a too-wide child under a tighter destination. Birth-parent lock does not follow the promoted spool.
- Proposed
Human Action - Prove
Password Unlock Request - Provenance
Read - Provenance
Result - Provider
Assembly Record - One record in output-pack order. Provider bytes must occupy an exact tiled physical range; inline bytes arrive as bounded ProviderInlineChunk frames. In either case the client verifies the encoded bytes and decoded object.
- Provider
Challenge - Provider
Connection - Provider
Consent - Provider
Dial Route - Authenticated transport hints only. The connected Iroh peer must still match provider.public_key; a URL is never a source of authority.
- Provider
Extent - Provider
Extent Event - Provider
Inline Chunk - Provider
Inline Source - Provider
Offer - Provider
Offer Extent - Capability-free candidate layout. It is not a serving grant. The client consents to its exact challenge before the issuer publishes ticket-bearing ProviderPlan; both phases use the same canonical layout commitments.
- Provider
Pack Location - Trusted issuer-to-provider control-plane registration. Never sent over the client Fetch stream. object_key names a private provider bucket object and must not appear in a client-visible ProviderPlan or ReadProviderExtent.
- Provider
Physical Range - A physical R2 range exactly tiled by independently hashed encoded records. record_set_commitment is a metadata commitment over pack identity, offset, length and ordered encoded record digests; it is not a hash of range bytes.
- Provider
Plan - Provider
Plan Challenge - An unsigned challenge carried over an already authenticated Fetch stream. Only the client’s exact-plan consent is signed. Both digests and the selected Thread/revision bind all tickets and virtual-pack placement.
- Provider
Plan Registration - Provider
Plan Registration Receipt - Provider
Range Chunk - Provider
Range Source - Provider
Read Ticket - The provider verifies this typed ticket against the published canonical extent set and the attenuated caller capability. A ticket alone grants no access; the opening’s native request proof binds the bearer key, the authenticated Iroh client peer matches client, and the receiver’s endpoint matches provider. Root rotation and expiry are independently checked.
- Provider
Repository - Provider
Result - Provision
Account Request - Invite-gated creation of an unclaimed human account. The independent root
slot stays empty. The agent proves its own key over this exact request using
principal:device-key:
; a human bearer cannot replace that proof. Existing key-bound accounts may be reused without an invitation. Reusing an operation ID with different bytes is rejected. - Provision
Account Response - Public
Handle Record - Public directory metadata contains no stable subject/account identifiers. ResolveResources supplies those only within an authorized resource scope.
- Public
Owner - A display label for a publicly visible account. Neither field grants access or supplies an owner verification key.
- Public
Principal Summary - Public presentation only; never carries credential, account settings or rights.
- Publication
Receipt - Publish
Content Client Frame - Publish
Content Finish - Publish
Content Open - Bulk content availability for an already admitted Thread capture. Metadata replication owns causal heads; uploading bytes cannot select or replace one. The opening PoP binds the exact Thread/revision, policy, complete pack/index addresses and lengths, operation identity, and any resume checkpoint.
- Publish
Content Server Frame - Purge
Operation Signing Body - Protobuf serialization is never signed. canonical_purge_operation_v2 is: u32_be(format_version), raw 16-byte spool_uuid, blob_hash as a u32-length- prefixed string, raw 32-byte payload_sha256, raw 32-byte leaf_capability_id. The leaf subject signs SHA-256(“heddle-purge-operation-v2” || canonical_body). The verifier binds this body to the actual spool, payload and direct PURGE grant. Moving the RPC package does not change this durable signing format.
- Purge
Sidecar Identity - PutApproval
Group Request - PutContext
Request - PutDelegation
Request - PutGrant
Request - PutPassword
Owner Setup Request - PutRecovery
Policy Request - PutReview
Policy Request - PutRun
Policy Request - Read
Artifact Request - Read
Budget - Read
Content Request - Read
Provider Extent Request - Record
Evidence Request - Record
Interaction Request - Record
Ref - Record
Review Request - Record
Signature - Recover
Checkout Request - Recovery
Argon2id Params - Recovery
Attempt - Recovery
Guardian - Recovery
Policy - The owner precommits to a threshold over distinct dedicated guardian keys. Product policy defaults to threshold >= 2 and a device-independent co-factor whenever Weft is a guardian. A 1-of-1 Weft policy is custodial and is allowed only after the client obtains the separately reviewed explicit confirmation.
- Redeem
Invitation Request - Redeem
Signup Invitation Request - A held shareable invitation code selects the admission directly; no lookup RPC, account bearer or device root is needed before choosing a passkey.
- Redeem
Signup Invitation Response - Refresh
Checkout Request - Register
Root Attachment Request - Register
Timeline Origin Request - Optional pre-expiry registration of an unchanged origin endorsement. Before the handler, middleware verifies a fresh method-bound Tier-1 proof. The caller must be an enrolled independent device root or active paired_credentials receiver_kind=device, with a persisted enrollment/pairing proof for its account, endpoint and proof key. Its authenticated effective uploader key MUST equal origin.uploader_device_public_key. In the write transaction, recheck its live credential, revocation, exact Thread/Spool writer authority, sharing destination/facet, billing and deletion gates. For a NEW registration, the complete origin chain must be live, unrevoked and unexpired at that transaction; the signature or client timestamp cannot date itself. Under (uploader account, client_operation_id), store registration_digest = SHA-256(UTF8(“heddle-timeline-registration-v1”) || 0x00 || counted(client_operation_id) || counted(spool UUID) || counted(ThreadId) || counted(run ID) || counted(origin_sha256)), where counted is u32be length plus exact bytes, UUIDs are canonical lowercase 36-byte ASCII, and origin_sha256 includes the complete signed endorsement. Transport PoP is excluded. Store the original server transaction timestamp beside the digest. A different digest for the same operation ID conflicts. An identical retry with a FRESH transport proof returns the original registered_at and digest, even after origin expiry, without re-dating or re-registering; it still checks current uploader, sharing, deletion and billing gates. Origin revocation invalidates the registered admission basis immediately. Registration never overrides revocation and never authorizes a later range by itself once the original has been revoked; fresh acceptance is then required.
- Register
Timeline Origin Response - Registration
Challenge - Registration
Recovery Policy - Release
Checkout Writer Request - Remote
Link Record - Removal
- Remove
Spool Mount Request - Rename
Passkey Request - Renames an account-owned passkey without changing its credential, owner, sign-in authority, or owner-signed PasskeyAuthority. A successful rename changes only the stored label and advances the passkey record version.
- Rename
Passkey Response - Rename
Thread Request - Renew
Ephemeral Session Request - Renews a short-TTL ephemeral (declined-enrollment) session in place. The renewal is proven by the caller’s existing ephemeral bearer plus a request PoP signed by the ephemeral key (CallContext.request_proof), so the body carries no session ref: the renewed session is exactly the caller’s own.
- Renew
Ephemeral Session Response - Reopen
Discussion Request - Replicate
Thread Request - Replicate
Thread Response - Replication
Have - Replication
Need - Replication
Open - Replication
Operations - Replication
Ready - Replication
Receipt - Replication
Rejection - Request
Held Handle Request - Request
Held Handle Response - Requirement
- Resolve
Checkout Request - Resolve
Discussion Request - Resolve
Handles Request - Resolve
Handles Response - Resolve
Invitation Request - Public capability preview. The invitation ID alone reveals nothing; the redemption secret is passed in the request body and never placed in a URL path or query. Invitation links get forwarded: any holder of the secret can see the spool address (including path segments) and name, role, expiry, inviter’s public handle and display name, and the delegated agent’s display label when present. The inviter’s handle also reveals that this person administers the spool, even if the spool is private. No recipient email is disclosed. The inviter lookup MUST use the same query shape for every status so timing does not reveal invitation validity.
- Resolve
Ownership Conflict Request - The original local owner chooses the winning account; that account’s currently authorized owner or delegate accepts. Neither arrival order nor a claimant’s signature alone adjudicates the conflict. Never implicit in upload/enrollment.
- Resolve
Resources Request - Resolve
Resources Response - Resolve
Signup Invitation Request - Resource
Ownership Transfer - Complete client-authored transfer. Missing either signature fails closed.
- Resource
Resolution - Resource
Selector - Account names and paths resolve to stable resources once. They never become authorization roots or replace the stable IDs in subsequent commands.
- Resource
Transfer Acceptance - Resource
Transfer Audit Record - Append-only result committed atomically with the resource-to-owner re-anchor. audit_record_hash is SHA-256(“heddle-resource-transfer-audit-v1” || the canonical transfer, commit time, and previous audit hash).
- Resource
Transfer Handoff - Canonical source offer for an atomic resource ownership re-anchor. canonical_resource_transfer_handoff_v1 encodes fields 1 through 8 in field order using fixed-width big-endian integers and length-prefixed byte strings. UUIDs are exactly 16 bytes, state hashes and nonce are exactly 32 bytes.
- Resume
Subscription Request - Retry
Import Source Request - Retry a failed native source fetch/adoption into its original Thread. The original operation remains immutable; this command creates a new operation and never creates a second Spool or Thread genesis.
- Review
Comparison - Exact comparison resolved within a review-section snapshot. A client submits these source/base/policy bytes when recording a decision; a Thread’s genesis base and an arbitrary source head are not substitutes for this binding.
- Review
Coverage - Review
Decision - Review
Policy Record - Review
Record - The observed decision and the exact portable signed control that authored it.
- Review
Symbol Anchor - Review
Symbols - Revise
Intent Request - Revise
Spool Request - Compare and replace display name and complete settings atomically. The stable UUID, parent, and immutable owner genesis are unchanged. Owner signature is not a prerequisite. The mere existence of a signed-policy tip does not block this RPC (independent CAS from expected_head). settings.audience / default_state_audience are bounded by the standing inherited max_audience (this spool and ancestors). Exceeding it is PERMISSION_DENIED.
- Revision
Ref - Revoke
Delegation Request - Revoke
Device Request - Revoke
Grant Request - Revoke
Invitation Request - Revoke
Provider Connection Request - Revoke
Session Request - Root
Attachment - User-root proof is portable. Account association records Weft’s acceptance of an already user-authorized key; it is not the source of that key’s authority.
- Root
Attachment Binding - Portable binding of a proved delegated key to its Iroh endpoint. Authority remains the Biscuit’s complete attenuation chain, not this locator binding. SignedRecord format heddle.root-attachment.v2 carries canonical bytes signed by both endpoint and subject (one signature when the keys are equal). The shared verifier requires a locally trusted root, verifies the Biscuit’s effective proof key and limits, then verifies digest, time and endpoint.
- RunArtifact
- RunEvent
- RunPermission
- RunPolicy
- RunRecord
- Search
Domain Status - Per-domain readiness is independent of result count and hidden matches. An unavailable index is not represented as an empty, complete result set.
- Search
Event - Search
Hit - Search
Request - Section
Replacement - Section
Status - Semantic
Index Artifact - Self-contained derived index, readable in one bounded artifact stream. Nodes are unique and sorted by hash; root_hash is 32 bytes and must name an included root. All derived root/tree/file nodes are included and verified. Opaque file entries may identify source commitments, but their raw source bytes are never included. Parsed/opaque counts describe this exact source.
- Semantic
Index Object - One existing Heddle semantic root/file/directory object. The canonical bytes use the versioned Heddle semantic index codec. The 32-byte hash uses Heddle’s Blob identity: BLAKE3(UTF8(“blob”) || uint64_le(canonical.length) || 0x00 || canonical), matching Blob::hash(). Hashing canonical alone is incorrect. This object grants no right to fetch other CAS objects.
- Session
Record - SetAttention
State Request - SetBookmark
Request - SetNotification
Preferences Request - SetRemote
Link Request - SetSpool
Mount Request - SetSupport
Access Request - SetThread
Audience Request - SetThread
Retention Request - SetThread
Sharing Request - Sharing
Destination - Sidecar
Authorization - Portable authorization for an exact purge, independently of its transport.
- Sign
Account Claim Request - Sign
Account Claim Response - Signed
Mint Root Attachment - Portable owner -> passkey -> temporary mint-key authorization. This v2 shape is the only SignedMintRootAttachment accepted for passkey sign-in.
- Signed
Owner Capability - Signed
Owner KeyTransition - Authorizations sign canonical_owner_key_transition_v1(transition).
- Signed
Owner Mint Root Attachment - Owner-signed account-bound attachment retained for registration of a durable independent mint root. Passkey authentication never accepts this shape: its account-free grant and owner-certified passkey chain use SignedMintRootAttachment below.
- Signed
Owner Root - Signed
Passkey Authority - Signed
Password Device Admission - Signed
Password Owner Setup Authorization - Signed
Policy Body - Signed
Policy Head - CAS predecessor. Independent of ReviseSpool.expected_version. Zero hash + sequence 0 = genesis.
- Signed
Policy Merge Rule - Signed
Record - A durable, versioned record. Its format defines canonical bytes, domain, signature algorithm, bounds and verifier. Generic protobuf serialization is never the signing input. Unknown critical formats fail closed.
- Signed
Resource Transfer Handoff - Signed
Spool Owner Genesis - Self-signed genesis evidence. owner_signature.signer_key_id MUST identify genesis.owner_public_key, and that key signs the exact 32-byte digest:
- Signed
Spool Policy - Offline-verifiable, owner-gated payload. NOT a copy of SpoolSettings. Substantive content: grow-only revocations + max_audience ceiling.
- Signed
Spool Policy Record - Signup
Invitation - Signup
Invitation Resolution - Signup
Reservation - Source
Anchor - Source
Conflict Candidate - Source
Conflict Set - A bounded set of immutable source alternatives observed at one checkout version. Candidate IDs are opaque and only meaningful within this version.
- Source
Location - Exact current coordinates, never an authoring input or a replacement for the original evidence in SourceAnchor. No implicit tracking from these fields.
- Source
Operation Frontier - Source
Target Reference - Shared by primary anchors and annotation references. This is a reference, never a grant to read the target’s source or its owning Thread.
- Source
Target Resolution - Source
Target Resolution Event - Shared map updates for anchors and tags. Snapshot/Upsert frames carry upsert; Remove frames carry remove. Deduplicate by key within a checkpoint batch. Maps clear with Thread collaboration / Spool context section replacement and replacement snapshots. Remove the entry when its last referrer leaves the observed window. Neither missing targets nor these events grant source access.
- Source
Target Resolution Key - Stable within an endpoint observation. Only a viewed_thread binding requires viewed_thread here; named and pinned bindings MUST omit it. The selected revision is a value, so capture moves one shared entry, not every referrer.
- Source
Target View - Exact view selection for a Thread’s inherited target bindings. This selects resolution only; it grants no source access and does not select more records.
- Spool
Address - Observed address of a stable Spool identity. Renames change the address, never the UUID. An address is presentation/routing metadata, not authority.
- Spool
Capability Grant - Spool
Creation Proof - Spool
Creation Statement - A creator’s statement of exact intended creation. created_at is NOT an admission timestamp. Only actual current admission or independently retained accepted evidence establishes whether this creation was permitted then. Canonical v1 fields follow tag order; domain “heddle-spool-creation-v1”.
- Spool
Event - Spool
Mount - Spool
Mutation Response - Committed overview and independently verifiable owner history seed the caller’s view directly. The receipt is not a trust root or a TOFU pin.
- Spool
Overview - Spool
Owner Genesis - Immutable owner-key binding created with a spool.
spool_uuidis the raw 16-byte UUIDv7 that is also the spool id.owner_public_keyis the owner authority key at creation; no registry key or nonce participates. - Spool
Pages - Spool
Ref - Spool
Selector - Spool
Settings - Fresh bootstrap permits child creation and has no implicit approval mandate. Explicit review policies still apply. A revision supplies the complete record; its settings participate in the observed review policy version.
- Stack
Landing - Each source is the exact revision supplied by the caller. For every distinct target, expected_target is compared once against the initial transaction snapshot. Ordered members then integrate into that target’s evolving frontier.
- Start
Analysis Request - Start
Thread Request - State
Read - Exact immutable source summary. Authored sidecars (including risk signals, conflict resolutions and semantic attachment attribution) are not source objects: use audience-checked Thread, checkout and Analysis projections. The selection emits one StateSummary followed by selection_complete.
- Store
Provider Credential Request - Stream
Checkpoint - Stream
Complete - Stream
Data - Stream
Frame - Stream
Heartbeat - Stream
Open - Stream
Reset - Submit
Owner Capability Request - Submit
Owner Transition Request - Submit
Recovery Proof Request - Submit
Recovery Proof Response - Submit
Signed Policy Request - Owner-signed spool policy submit. Not a prerequisite of ReviseSpool. request.spool MUST equal record.body.spool_uuid; mismatch fails closed. Proposed max_audience, if present and specified, MUST be <= the ancestors’ effective ceiling (min over ancestors only). Retry by client_operation_id. The biscuit RESOURCE_OWNER role is necessary but not sufficient: the verifier checks the owner signature against the server-derived current owner OwnerState. Receipt binds SignedPolicyHead (Decision 8).
- Submit
Signed Policy Response - Support
Access Record - Synchronize
Remote Request - Thread
Audience Policy - Thread
Control Authority - Original author evidence bound into each signed Thread metadata operation. Supplied history never establishes trust: receivers verify against separately admitted current account authority at first durable admission. Canonical protobuf encoding is mandatory and the entire envelope is bounded to 64 KiB.
- Thread
Event - One typed stream composes a Thread’s decision context. Common frame controls have no payload. Every data frame carries exactly one payload; snapshots and delta batches become visible only at their checkpoint. SectionReplacement.section and SectionStatus.section use these exact keys: overview (overview); captures (capture); review (comparison, review, diff); evidence (evidence, check_acknowledgement); collaboration (discussion, turn, context, source_target); analysis (analysis); checkouts (checkout); timeline (timeline_event, run, operation); sharing (sharing, publication). Replacement clears only that section’s committed collection. V1 timeline “operation” is explicitly empty. Timeline always reports a section status, including an eligible empty collection. Timeline run/event frames reuse RunRecord/TimelineRecord output, ordered by server change sequence; recorded_at is display time only. Removal uses Removal. A lost timeline membership proof or change-log continuity ends with Reset then FIN. Resource-reader and Thread/Spool audience rights are ceilings. A run/event is visible only to its verified direct-human principal account or a live same-principal agent whose final effective PoP key digest exactly equals the run’s frozen actor digest. Agent labels, Thread/Spool owner and admin roles never override that predicate. Join current sharing epoch, audience, billing/deletion gates and the payload deadline before order, limit or count. Forbidden and absent run IDs, pages and cursors have identical status, count, cursor and Reset shapes. No hidden append advances a visible cursor. Every eligibility-bearing frame gets a fresh current database authorization check immediately before handoff; expiry wakes idle followers without a sweep. Unknown section semantics require a fresh supported view, never silent loss.
- Thread
Genesis Record - Carries original ownership proof with the immutable creator-signed identity. The receiver independently verifies it; transport credentials never select the owning account or enroll an otherwise-untrusted account root.
- Thread
Id - Thread
Intent - Thread
Invitee - Thread
List Event - Thread
Metadata Conflict - Thread
Mutation Response - Thread
Name Selector - Thread
Overview - Thread
Ownership - Thread
Ownership Conflict - Thread
Pages - Independent section windows share one observation’s total read budget. Missing windows select bounded defaults only for requested sections.
- Thread
Property Frontier - Thread
Query - Thread
Ref - Thread
Relationship - Thread
Retention Policy - Thread
Sharing Policy - Timeline
Acceptance Scope - V2 grant scope. This names the ORIGINAL credential, not the accepting subject key or an agent display label. All fields are mandatory and exact.
- Timeline
Admission Acceptance - A current direct-human run-principal authority or a current v2
OwnerAuthorizationBundle (owner_records.proto) with an
ACCEPT_TIMELINE_ORIGIN grant signs this exact acceptance:
UTF8(“heddle-timeline-run-acceptance-v1”) || 0x00 followed by fields 1..6
below, then one authority byte (1 for principal credential, 2 for owner
capability) and counted(exact authority bytes). Byte fields use
u32be(length)||bytes, uint64 fields use u64be, and event_count uses u32be.
The signature and transport PoP are excluded. The original digest is
SHA-256 of the origin transcript plus
its 64-byte signature. The request digest is SHA-256 of:
UTF8(“heddle-timeline-upload-v1”) || 0x00 || counted(client_operation_id)
|| counted(spool UUID) || counted(ThreadId.value) || counted(run ID)
|| u32be(canonicalization_version) || u64be(run_revision)
|| one byte snapshot presence || [u32be(state)||counted(harness) if present]
|| u32be(event count), then for each event in wire order:
u64be(position)||u32be(kind)||i64be(recorded_at.seconds)
||u32be(recorded_at.nanos)||one byte tool presence
|| [u32be(tool) if present]
|| counted(origin SHA-256) || u64be(first_position).
countedmeans u32be(byte_length)||exact bytes; presence is 0 or 1. The acceptance, its authority selector and transport PoP are excluded. Unknown fields are invalid. This layout is independent of protobuf serialization. An acceptance is valid only for this exact digest and position range. For principal_credential_id, Weft resolves the exact ID in its current credential registry, verifies a live independent root or server-issued direct-human session/pairing chain, and uses that chain’s final effective Ed25519 PoP key for this signature. Its account MUST be the origin’s verified principal. Agent labels, account claims and uploader credentials do not confer acceptance permission. For owner_derived_capability, the bytes are a protobuf wire encoding of OwnerAuthorizationBundle, at most 4096 bytes. Decode the complete bundle, rejecting unknown fields and trailing bytes. Verify its owner root and transition history against the independently pinned CURRENT owner state of the run-principal account; OwnerRoot.account_uuid MUST equal the verified principal UUID (never accept a state supplied only by this bundle). Then verify the single format-2 capability and subject Biscuit. The grant’s exact Spool selector, Thread ID, original principal UUID, credential class, original credential ID, effective key digest and signed origin SHA-256 MUST equal the verified origin. The leaf CapabilityPrincipal.key is the effective Ed25519 signing key for this acceptance. SignedOwnerCapability.signature signer_key_id instead resolves to the owner issuer key through the accepted owner transition at issuer_state_hash and its live rotation/recovery signing window; reject an obsolete, vetoed or uncommitted issuer state. The subject signs this acceptance transcript with its effective key, not the owner key or the uploader key. Recheck capability validity interval, direct-only/single-block attenuation restriction, active owner transitions/recovery windows, every credential and capability revocation, and the subject proof at the admission transaction. No v1 PURGE grant, generic grant envelope, passkey certificate alone, or owner/admin status authorizes acceptance. The acceptance bytes do not replace the uploader’s independent Tier-1 transport proof. - Timeline
Origin Endorsement - The active origin credential signs this exact transcript with Ed25519: UTF8(“heddle-timeline-run-origin-v1”) || 0x00, then, in field order below, each byte/string field as u32be(byte_length) || its exact bytes; class is one unsigned byte (1 or 2). UUIDs are 36 lowercase ASCII bytes in canonical hyphenated form. The signature itself is excluded. No protobuf serialization, client timestamp or hash of a reconstructed RunRecord is a signing input. Weft verifies the complete persisted origin chain and effective proof key.
- Timeline
Record - Transfer
Checkpoint - Transfer
Object - Transfer
Ownership Request - Transfer
Ready - Transfer
Selection - Transfer
Sidecar - Tree
Read - Unsubscribe
Notifications Request - Public, single-purpose disabling action. The opaque capability determines the recipient and exact allowed selectors; no account credential is required. Each requested rule must select an authorized channel and DISABLED delivery.
- Update
Subscription Request - Upload
RunSummary - Dedicated upload summary: only the two allowlisted v1 fields.
- Upload
Scrubbed Timeline Ack - Upload
Scrubbed Timeline Request - One logical request for one Spool/Thread/run; encoded request <= 256 KiB. The full batch commits atomically. Every attempt needs a fresh method-bound Tier-1 PoP nonce/timestamp, including an identical retry. The authenticated uploader is an enrolled independent device root or active paired device as above, and its effective key must match the immutable origin uploader key. Under the Spool/Thread lock first admission enforces unique (spool_id,run_id) across ALL Threads and sharing epochs, and freezes the exact Thread, principal, actor class/effective key digest, uploader account/key and first sharing epoch. A different Thread or uploader cannot re-admit that run. Before accepting a new operation ID, check both the live run and durable keyed run fence across epochs. A purged run cannot be resurrected with a new operation ID, origin signature, or sharing re-enable. Retain the terminal operation digest fence and run HMAC fence after expiry, DISCARD or sharing purge, including runs with no policy deadline. Delete them with Thread/Spool deletion or relevant account/billing-lock deletion; the durable deletion fence then makes old attempts uniformly absent. A first upload requires a live origin chain at transaction time, an exact previously registered pre-expiry origin that has not since been revoked, or fresh scoped acceptance of this request. Later batches recheck the recorded admission basis and acceptance range, plus current uploader, sharing, billing, deletion, retention and revocation gates in the transaction.
- Upload
Scrubbed Timeline Response - Upload
Timeline Event - Dedicated event input; canonical encoded event size is at most 2048 bytes.
- Upload
Timeline Position Gap - Verified
Email Reservation - Verify
Evidence Request - Verify
Evidence Response - Veto
Owner Transition Request - Veto
Recovery Request - Weft
Custody Recovery Policy Selection - The only supported custodial recovery shape is exactly one WEFT guardian with threshold one. It is never inferred from an omitted selection.
- Weft
Custody Warning Consent - Versioned evidence that the user saw and accepted the exact 1-of-1 Weft custody warning. warning_sha256 is SHA-256 of the reviewed UTF-8 warning text for warning_version; unknown versions and digests fail closed.
- Workspace
Event - Workspace
Pages
Enums§
- Account
Deletion Outcome - Analysis
Kind - Audience
- Existence/history audience for a spool. Numeric tags match v1 Visibility (PRIVATE=1, INTERNAL/MEMBERS=2, PUBLIC=3). Do not add AUDIENCE_INTERNAL.
- Authorization
KeyAlgorithm - Behavior
Correspondence Kind - Behavior
Limitation - Behavior
Match Reason - Behavior
Provenance - Behavior
Support - Billing
Interval - Capability
Principal Kind - Catalog
Sort - Public resource discovery never includes private grants, devices or account attention. Exact public content still uses the ordinary resource read APIs.
- Clone
Owner PinKind - Coverage
- Credential
Kind - Credential
Method - Explicit ceremony selection; omitted or unsupported methods are rejected. Password unlocks a client-held owner key; OAuth retains its own ceremony. Neither a password verifier signature nor an OAuth proof is owner authority.
- Endpoint
Kind - Handle
Kind - Hold
Lifecycle - Delegated HOLD-verdict lifecycle on SpoolSettings. Not abandoned_thread_retention. v1 VersionedHoldLifecycle was chain-inherited and offline-citable; moving HOLD here drops that citation. UNSPECIFIED inherits; the built-in root default is EXPLICIT_SUPERSESSION.
- OAuth
Provider - Observation
Mode - Shared observation protocol. Each RPC has a typed event payload alongside StreamFrame. Only a data frame carries a payload. See docs/alpha-v2/streams.md. A logical RPC occupies one reliable, ordered Iroh stream; this contract does not turn protobuf frames into unreliable UDP datagrams.
- Owner
KeyBinding Kind - Owner
KeyTransition Kind - Recovery
Guardian Kind - Recovery-key provenance is part of the signed policy. A verifier can distinguish paper, social, and Weft guardians when counting signatures.
- Requirement
Kind - Resource
Role - Review
Readiness - Rooting
Tier - Account onboarding state, never a substitute for a verified capability or owner-root binding. Promotions are explicit; a credential’s attenuation must survive promotion of its account. AGENT_ROOTED denotes an unclaimed human account with an empty independent-root slot, not an account owned by an agent.
- Search
Domain - Search
Match Kind - How this match was established; score is only comparable within this query.
- Search
Source History - Which accepted source revisions participate in content and symbol search.
- Seat
Pricing Mode - Shared
Facet - Signed
Policy Merge Semantics - Spool
Capability Action - Spool
Section - Stream
Data Kind - Stream
Reset Reason - Subscription
Status - Provider IDs, API credentials and webhook secrets never appear in this contract. Weft resolves the authenticated account and checks the credential’s effective delegated billing authority for every read and mutation.
- Thread
Lifecycle - Thread
Property - Thread
Section - Timeline
Origin Credential Class - Timeline
Start - Selects where a single run’s timeline observation begins. This does not change the default oldest-first collection pagination.
- Upload
Timeline Event Kind - Upload
Timeline Tool - User
Verification