Expand description
Frozen Thread-oriented contract; endpoint support is negotiated.
Modules§
- analysis_
event - Nested message and enum types in
AnalysisEvent. - analysis_
finding - Nested message and enum types in
AnalysisFinding. - annotation_
property_ predicate - Nested message and enum types in
AnnotationPropertyPredicate. - annotation_
tag - Nested message and enum types in
AnnotationTag. - annotation_
tag_ predicate - Nested message and enum types in
AnnotationTagPredicate. - annotation_
value - Nested message and enum types in
AnnotationValue. - artifact_
event - Nested message and enum types in
ArtifactEvent. - attention_
event - Nested message and enum types in
AttentionEvent. - attention_
item - Nested message and enum types in
AttentionItem. - begin_
pairing_ request - Nested message and enum types in
BeginPairingRequest. - begin_
registration_ request - Nested message and enum types in
BeginRegistrationRequest. - behavior_
assignment - Nested message and enum types in
BehaviorAssignment. - behavior_
branch - Nested message and enum types in
BehaviorBranch. - billing_
event - Nested message and enum types in
BillingEvent. - blob_
read - Nested message and enum types in
BlobRead. - bookmark_
ref - Nested message and enum types in
BookmarkRef. - capture_
summary - Nested message and enum types in
CaptureSummary. - catalog_
event - Nested message and enum types in
CatalogEvent. - check_
evidence_ summary - Nested message and enum types in
CheckEvidenceSummary. - checkout_
event - Nested message and enum types in
CheckoutEvent. - collaboration_
anchor - Nested message and enum types in
CollaborationAnchor. - collaboration_
event - Nested message and enum types in
CollaborationEvent. - complete_
authentication_ request - Nested message and enum types in
CompleteAuthenticationRequest. - complete_
pairing_ request - Nested message and enum types in
CompletePairingRequest. - complete_
registration_ request - Nested message and enum types in
CompleteRegistrationRequest. - content_
event - Nested message and enum types in
ContentEvent. - content_
read - Nested message and enum types in
ContentRead. - content_
tree_ entry - Nested message and enum types in
ContentTreeEntry. - control_
run_ request - Nested message and enum types in
ControlRunRequest. - create_
spool_ request - Nested message and enum types in
CreateSpoolRequest. - credential_
result - Nested message and enum types in
CredentialResult. - delegation_
record - Nested message and enum types in
DelegationRecord. - discussion_
record - Nested message and enum types in
DiscussionRecord. - effective_
delivery - Nested message and enum types in
EffectiveDelivery. - entity_
ref - Nested message and enum types in
EntityRef. - fetch_
client_ frame - Nested message and enum types in
FetchClientFrame. - fetch_
open - Nested message and enum types in
FetchOpen. - fetch_
server_ frame - Nested message and enum types in
FetchServerFrame. - get_
definition_ response - Nested message and enum types in
GetDefinitionResponse. - get_
import_ job_ state_ response - Nested message and enum types in
GetImportJobStateResponse. - get_
semantic_ refs_ request - Nested message and enum types in
GetSemanticRefsRequest. - handle_
resolution - Nested message and enum types in
HandleResolution. - identity_
event - Nested message and enum types in
IdentityEvent. - import_
report - Nested message and enum types in
ImportReport. - integration_
event - Nested message and enum types in
IntegrationEvent. - invitation_
resolution - Nested message and enum types in
InvitationResolution. - landing_
assessment_ status - Nested message and enum types in
LandingAssessmentStatus. - list_
paths_ event - Nested message and enum types in
ListPathsEvent. - material_
retention - Nested message and enum types in
MaterialRetention. - mutation_
receipt - Nested message and enum types in
MutationReceipt. - notification_
event - Nested message and enum types in
NotificationEvent. - notification_
rule - Nested message and enum types in
NotificationRule. - o_
auth_ proof - Nested message and enum types in
OAuthProof. - operation_
event - Nested message and enum types in
OperationEvent. - operation_
record - Nested message and enum types in
OperationRecord. - operation_
subject - Nested message and enum types in
OperationSubject. - ownership_
event - Nested message and enum types in
OwnershipEvent. - pack_
extent - Nested message and enum types in
PackExtent. - pairing_
event - Nested message and enum types in
PairingEvent. - pairing_
initiation_ binding - Nested message and enum types in
PairingInitiationBinding. - pairing_
record - Nested message and enum types in
PairingRecord. - presence_
event - Nested message and enum types in
PresenceEvent. - provider_
assembly_ record - Nested message and enum types in
ProviderAssemblyRecord. - provider_
dial_ route - Nested message and enum types in
ProviderDialRoute. - provider_
extent_ event - Nested message and enum types in
ProviderExtentEvent. - provider_
ref - Nested message and enum types in
ProviderRef. - publication_
receipt - Nested message and enum types in
PublicationReceipt. - publish_
content_ client_ frame - Nested message and enum types in
PublishContentClientFrame. - publish_
content_ server_ frame - Nested message and enum types in
PublishContentServerFrame. - record_
interaction_ request - Nested message and enum types in
RecordInteractionRequest. - registration_
recovery_ policy - Nested message and enum types in
RegistrationRecoveryPolicy. - remote_
link_ record - Nested message and enum types in
RemoteLinkRecord. - replicate_
thread_ request - Nested message and enum types in
ReplicateThreadRequest. - replicate_
thread_ response - Nested message and enum types in
ReplicateThreadResponse. - resolve_
discussion_ request - Nested message and enum types in
ResolveDiscussionRequest. - resource_
selector - Nested message and enum types in
ResourceSelector. - review_
coverage - Nested message and enum types in
ReviewCoverage. - review_
decision - Nested message and enum types in
ReviewDecision. - revision_
ref - Nested message and enum types in
RevisionRef. - run_
event - Nested message and enum types in
RunEvent. - satisfied_
policy_ requirement - Nested message and enum types in
SatisfiedPolicyRequirement. - search_
event - Nested message and enum types in
SearchEvent. - search_
request - Nested message and enum types in
SearchRequest. - set_
attention_ state_ request - Nested message and enum types in
SetAttentionStateRequest. - signup_
invitation_ resolution - Nested message and enum types in
SignupInvitationResolution. - source_
target_ reference - Nested message and enum types in
SourceTargetReference. - source_
target_ resolution - Nested message and enum types in
SourceTargetResolution. - source_
target_ resolution_ event - Nested message and enum types in
SourceTargetResolutionEvent. - spool_
creation_ proof - Nested message and enum types in
SpoolCreationProof. - spool_
event - Nested message and enum types in
SpoolEvent. - stream_
frame - Nested message and enum types in
StreamFrame. - submit_
owner_ transition_ request - Nested message and enum types in
SubmitOwnerTransitionRequest. - submit_
recovery_ proof_ request - Nested message and enum types in
SubmitRecoveryProofRequest. - submit_
recovery_ proof_ response - Nested message and enum types in
SubmitRecoveryProofResponse. - thread_
audience_ policy - Nested message and enum types in
ThreadAudiencePolicy. - thread_
control_ authority - Nested message and enum types in
ThreadControlAuthority. - thread_
event - Nested message and enum types in
ThreadEvent. - thread_
list_ event - Nested message and enum types in
ThreadListEvent. - thread_
ownership - Nested message and enum types in
ThreadOwnership. - thread_
query - Nested message and enum types in
ThreadQuery. - thread_
relationship - Nested message and enum types in
ThreadRelationship. - timeline_
admission_ acceptance - Nested message and enum types in
TimelineAdmissionAcceptance. - timeline_
origin_ credential_ identity - Nested message and enum types in
TimelineOriginCredentialIdentity. - transfer_
sidecar - Nested message and enum types in
TransferSidecar. - upload_
scrubbed_ timeline_ response - Nested message and enum types in
UploadScrubbedTimelineResponse. - veto_
recovery_ request - Nested message and enum types in
VetoRecoveryRequest. - workspace_
event - Nested message and enum types in
WorkspaceEvent.
Structs§
- Acknowledge
Check Request - Action
Availability - Agent
Ref - Stable delegated agent identity, scoped to its owning account. Neither a display name nor a rotating signing key is an agent’s resource identity.
- Analysis
Artifact - Immutable derived analysis output. Stored under an opaque Thread-scoped artifact identity; this is never an authorization wrapper for source bytes. Readers decode one canonical message, not concatenated stream frames. The producer rejects outputs larger than its advertised artifact byte budget.
- Analysis
Event - Analysis
Finding - Analysis
Record - Annotation
Decimal - Structured context metadata. References describe a target; they grant no access to it and never change the annotation’s primary anchor or audience.
- Annotation
Property - Annotation
Property Predicate - Annotation
Query - Annotation
Source Reference - Annotation
Symbol Tag - Annotation
Tag - Annotation
TagPredicate - Annotation
Value - Anonymous
Session Response - Append
Discussion Request - Applied
- Approval
Group Record - Approve
Pairing Request - Artifact
Event - Attach
Provider Installation Request - Attach a GitHub App installation that became available after OAuth consent. The hosted service validates the exact installation against the caller’s stored provider credential before updating the connection.
- Attention
Event - Attention
Item - Authentication
Challenge - Authentication
Response - Authorization
Signature - Authorization
Verification Key - Begin
Authentication Request - Begin
Checkout Request - Begin
Custodial Recovery Request - Begin
Custodial Recovery Response - Begin
Email Verification Request - Begin
Pairing Request - Begin
Pairing Response - Begin
Provider Connection Request - Begin
Recovery Request - Begin
Recovery Response - Begin
Registration Request - Behavior
Analysis Coverage - Behavior
Assignment - Behavior
Binding - Behavior
Branch - Behavior
Byte Span - Behavior
Change - A self-contained structural map. Typed containment (assignment.value_id, conditional.predicate_id), selection (branches), binding and correspondence are distinct. This version emits no inferred consequences or test approval; resolved call/reference graph edges remain independent evidence and cannot establish execution order or effects. All referenced IDs must occur here.
- Behavior
Change Removal - Behavior
Conditional - Behavior
Correspondence - Behavior
Dependencies - Behavior
Expression - Behavior
Operation - Behavior
Scope - Each entry describes only this analyzer’s supported pattern, not all behavior in a file or file group. Empty supported scope means no supported changes; omitted scope, partial analysis and interrupted streams are different states.
- Behavior
Source - Source navigation is pinned to bytes, never just a semantic digest. Byte offsets are zero-based, half-open UTF-8 byte ranges. No inferred locations.
- Behavior
Versions - Billing
Event - Billing
Plan - Billing
Record - Billing
Redirect Response - Billing
Seat Pricing - Billing
Seat Tier - Blob
Chunk - Blob
Read - Blocked
- Bookmark
Mutation Response - Bookmark
Record - Bookmark
Ref - Caller-private preference identity; changing it never changes its target.
- Bootstrap
Ownership Request - Browser
Pairing Approval Binding - Browser
Pairing Completion Binding - SignedRecord format heddle.browser-pairing-completion.v1. The current subject key signs domain || deterministic protobuf bytes plus a fresh exact RPC proof.
- Browser
Pairing Receiver - Provisional two-key possession, before an approving account is known. SignedRecord format heddle.pairing-initiation.v2; each actual receiver key signs domain || protobuf bytes in ascending tag order, omitting scalar defaults. Oneof presence is preserved. The host and operation prevent reuse. Credential-only receiver. Its subject key is not an Iroh endpoint.
- Cancel
Import JobRequest - Cancel
Operation Request - Cancel
Subscription Request - Capability
Principal - Capture
Checkout Request - Capture
Summary - Catalog
Activity Summary - Counts of public activity on one catalog Spool. A server deriving these from rollups may serve eventually consistent values; they are display hints, not authorization or a transactional snapshot of underlying Threads/changes.
- Catalog
Event - Catalog
Filter - All predicates are ANDed with query over caller-visible public catalog rows. Absent or empty means no filtering. See docs/alpha-v2/catalog.md.
- Catalog
Leader - Linkable public leader even when its row is outside the requested page. Only already-public labels; never private ancestry or owner identity.
- Catalog
Summary - One snapshot per catalog snapshot, independent of page size or sort. No live refresh. Same query/filter and caller-visible public rows as catalog paging. Private Spools/activity MUST NOT affect counts, leaders, approximation or other observable summary metadata. See docs/alpha-v2/catalog.md.
- Causal
Frontier - A causal frontier is portable within its exact Thread/facet/format. It is never an Observe cursor or a bulk-transfer checkpoint. Heads are paged using the negotiated max_items; repeated Have frames contribute to the same round.
- Change
Thread Lifecycle Request - Check
Acknowledgement Record - Immutable review progress for one accepted check result and exact policy. This does not change its outcome, supersede evidence or grant landing approval.
- Check
Evidence Currency - Check
Evidence Summary - Derived presentation of canonical signed evidence. The receiving endpoint verifies original authority independently; a reported pass is not itself cryptographic proof that an external process ran correctly.
- Checkout
Event - Checkout
Mutation Response - Checkout
Overview - Checkout
Ref - Checkout
Writer Lease - The same physical-checkout lease is enforced by CLI and device RPCs. Possessing its token never grants authority: each mutation also authenticates the owner session, verifies current capability, and compares source/version.
- Claim
Checkout Writer Request - Claim
Checkout Writer Response - Claim
Handle Request - Claim
Handle Response - Claim
Thread Ownership Request - The owner and accepting account publisher co-sign one exact canonical claim. Upload and device enrollment never invoke this transition implicitly.
- Claim
Thread Ownership Response - Client
Owned Credential - Clone
Authorization Keyring - Clone
Owner Pin - Local provenance chosen and persisted by the client. There is no UUID-to-key migration or legacy TOFU arm: all accounts start owner-anchored.
- Code
File Position - Code
Importer - Code
Navigation Metadata - Code
Occurrence - Code
Position - Code
Semantic Ref - Original source-to-target orientation, also for incoming/caller queries.
- Code
Span - Code
Symbol - Code
Symbol Address - SymbolAnchor’s path + container::path::name spelling at this exact revision. Neither symbol_id nor semantic_hash alone identifies a unique definition.
- Collaboration
Anchor - Collaboration
Event - Commit
Import JobRequest - Prepare -> sign -> Commit is sufficient for a new HYBRID import. Defined here to reuse ProviderRepository without an import cycle. Proof originals and the signed ordered branch manifest are the ONLY branch carrier. Maximum decoded protobuf request size: 2 MiB (2097152 bytes), inclusive; proof <=1 MiB (1048576 bytes), inclusive. Enforce the whole uncompressed payload bound before decoding, and the decoded message bound before admission.
- Complete
Authentication Request - Complete
Email Verification Request - Complete
Email Verification Response - Complete
Owner Transition Request - Complete
Pairing Request - Complete
Provider Connection Request - Complete
Recovery Request - Complete
Registration Request - Content
Event - Content
File - Content
Read - Content
Spool Link - Content
Tree Entry - Context
Draft - Write input. Actor attribution is carried by the signed canonical operation; coverage and current-view versions are server projections, never client input.
- Context
Record - Control
RunRequest - Create
Anonymous Session Request - Anonymous continuity has no human account and no independent owner root. The endpoint retains its existing anti-abuse, expiry and rotation checks.
- Create
Billing Portal Request - Create
Invitation Request - Create
Invitation Response - Create
Signup Invitation Request - Create
Signup Invitation Response - Create
Spool Request - Credential
Inspection - Credential
Result - Returned only by a successful credential ceremony, never by an observation. Keyed clients retain their own minting authority. Registration attaches their proved key to an account/session; it does not mint a bearer or confer an independent human root on an agent. Other keyless ceremonies can return an issued bearer. Password completion MUST return client_owned, never issued.
- Current
Credential Record - Metadata for the exact credential authenticating this observation. This is not issuance, and neither account tier nor account role upgrades its rights.
- Custodial
Email Binding - Fixed-width canonical v1: u32 version, raw16 account UUID, raw16 attempt UUID, raw32 proposed Ed25519 root, raw32 challenge, i64 expiry (big endian). Email possession authorizes only this attempt, never account/spool access.
- Custodial
Email Proof - Custodial
Recover Proposal - Custodial
Recovery Details - Decide
RunPermission Request - Delegated
Import Operation V1 - Delegation
Credential Response - Delegation
Record - Delete
Account Request - Irreversibly deletes the caller’s account. The authenticating credential MUST be the direct account owner’s proof-bearing credential: agent, service, delegated, derived and attenuated credentials are rejected even if they otherwise carry caller-bound account authority. confirmation_handle MUST exactly equal the account’s current handle. Reusing client_operation_id returns the original outcome without deleting or canceling anything twice.
- Delete
Account Response - Delete
Approval Group Request - Delete
Password Owner Setup Request - Delete
Review Policy Request - Delete
Spool Request - Describe
Endpoint Request - Describe
Endpoint Response - Device
Identity - Diff
Read - Discussion
Action Availability - Caller-specific advice following ActionAvailability’s conventions. A typed action also describes blocking changes without inventing a mutation RPC or changing the signed collaboration format. Advice never grants authority.
- Discussion
Record - Discussion
Resolution Record - Server-derived admission metadata for one original signed resolution. NOT part of ResolveDiscussionRequest or the canonical author-signed operation; neither the client nor the courier can assert an override. Retain the rule and marker at admission, never recompute history from today’s spool settings. This projection is not an offline-verifiable authorization proof.
- Discussion
Turn - Effective
Delivery - One concrete resolved delivery, using the same selectors as a stored rule. kind and channel are concrete (never wildcard); actor_origin is human/agent, or empty for a kind whose delivery is independent of origin. spool absent is account scope. source must be RULE or DEFAULT; delivery must be concrete. An off effective digest interval resolves email DIGEST to DISABLED without changing the stored rule or its source. Destination readiness is separate.
- Email
Verification Challenge - Only the endpoint’s authenticated, independently rooted signup-mailer service account may begin delivery. Its bearer is the possession factor.
- Endpoint
Ref - Entitlement
Record - Entity
Ref - Evidence
Record - Evidence
Verification - Expected
Version - Fetch
Client Frame - Fetch
Complete - Fetch
Open - Fetch
Server Frame - GetCustodial
Recovery Attempt Request - GetCustodial
Recovery Attempt Response - GetDefinition
Request - GetDefinition
Response - GetFile
Symbols Request - GetFile
Symbols Response - GetHosted
Witness History Proof Request - Public digest-holder policy, survives deletion and lost read grant. No batch, listing, prefix or pagination. Validate exactly 64 bytes before archive I/O.
- GetHosted
Witness History Proof Response - Proof ONLY. Uniform NOT_FOUND for unknown ID, leaf or unsealed archive. At most 64 siblings and 4096 encoded bytes, no original/resource identifiers.
- GetIdentity
Request - Bounded unary identity lookup for one-shot callers. The principal is always returned; callers can opt into metadata for the authenticating credential.
- GetIdentity
Response - GetImport
Configuration Request - An authenticated finite read, separate from provider inventory observation. Configuration is advice, never authority; Prepare and Commit recheck current support and refuse totals above the current advertised host maximum.
- GetImport
Configuration Response - GetImport
JobState Request - Destination-writer-only, authenticated finite read. No listing, pagination or seed/custody/bearer secrets. Unknown and unauthorized jobs use uniform NOT_FOUND. Discover destination + logical_job_id from OperationRecord.ref.spool and subject.import.hybrid_job; selector visibility grants no read/control authority.
- GetImport
JobState Response - GetSemantic
Importers Request - GetSemantic
Importers Response - GetSemantic
Refs Request - Single-revision envelope re-homing weft#2021. Do not merge graphs across revisions or Threads. CALLEES_OF additionally serves the impact-graph consumer.
- GetSemantic
Refs Response - Grant
Record - Group
Requirement - Guardian
Recovery Policy Selection - Registration defaults to this guardian M-of-N policy. If OwnerRegistration.recovery is absent, the policy in the signed root is treated as this branch and MUST contain a valid threshold and at least one non-WEFT guardian. Absence never selects Weft custody.
- Handle
Resolution - Harness
Preference - Hosted
Landing Request Proof V1 - Retained exact Tier-1 signing preimage + original signature; no bearer secret.
- Hosted
Landing Witness V1 - Hybrid
Import JobSelector - HYBRID logical-job discovery only; destination is OperationRecord.ref.spool. Not a physical operation ID, retry lineage, client operation ID or authority.
- Identity
Event - Import
Authority Witness V1 - Import
Boundary Acceptance V1 - Typed purpose payloads use the same fixed-order canonical framing. SignedRecord flattens counted format, counted original native bytes, signature count then counted key/signature pairs, sorted by raw key. Native bytes are never changed. Complete exact native evidence, never reconstructed from sidecar identifiers. The acceptance signature commits to the complete manifest and intent native IDs. Native verification checks selected originals and each receipt’s exact basis.
- Import
Branch Limit V1 - One authorized result slot. First release permits one result per branch; slot_id is stable across physical retries under the job’s single certificate. Reservation identity is (spool UUID, full ref, slot_id), not slot_id alone. Full refs are exclusive across all non-terminal jobs in the same spool.
- Import
Branch Manifest V1 - Import
Budget Limits V1 - Import
Committed Slot V1 - Import
Content V1 - Import
Converter Configuration V1 - Import
Eligible Retry Target V1 - Narrow writer-only disclosure; does not expose a full OperationRecord or change ordinary OperationService visibility. Same destination/job/lineage.
- Import
Frontier V1 - Frozen cross-model SHA256 preimages, not native object IDs. Operation IDs are original native Thread operation IDs; complete sorted unique source frontier.
- Import
Genesis Authority V1 - Import
Genesis Witness V1 - Import
Identity V1 - Import
JobDelegation V1 - The browser copies every field from ImportJobPreparationV1 byte-for-byte, adds only fields 8, 9, 13 (binding digests, never limits), 14 and 15, and signs the complete body. Prepare supplies no placeholders for these fields.
- Import
JobPreparation V1 - Exact server-frozen projection of ImportJobDelegationV1. No signer, parent permission, genesis-binding digests or validity window exists at Prepare. Canonical bytes use numbered-field order and the framing above. Commit must compare this projection byte-for-byte with the stored reservation.
- Import
Member Permission V1 - P2 #1: NEW direct owner -> device permission, unrelated to PURGE, timeline, self-PoP or online Developer/Admin grants. Exactly one logical job/lineage; grants genesis binding and bounded IMPORT_CONVERSION delegation, no device subdelegation. Durable accounting is (permission digest, logical job) and slot identity is (logical job, branch, slot); byte totals never reset by key/retry.
- Import
Operation Subject - Import
Owner Chain V1 - Recomputed from independently verified owner histories and handoff audits, not an incoming digest. State hashes are sorted unique, transfer hashes are in accepted sequence order. The histories retain every original signature.
- Import
Permission Scope V1 - Import
Preparation Refusal V1 - Import
Provider Configuration V1 - Import
Public Proof Bundle V1 - Owner verification belongs to heddle capability-verifier: independently select the immutable lineage, verify owner histories/handoffs and current or witnessed historical authority. This public carrier cannot enroll its owner.
- Import
Publication Witness V1 - Import
Report - Import
Result Manifest V1 - Import
Source Request - Closed route: always FAILED_PRECONDITION with typed ERROR_REASON_IMPORT_SOURCE_REQUIRES_COMMIT after authentication/authorization. Never creates, attaches, aliases Commit or activates a HYBRID job. Use Commit for initial submission and RetryImportSource for an existing physical job.
- Import
Source Selection V1 - Explicit custody selector. The URL is proposed_scope.source_url. The host resolves this selector for the authenticated caller at Prepare and Commit; a domain alone NEVER selects credential custody. Identifiers/visibility only: no credentials, grants or execution authority.
- Integration
Event - Introspect
Credential Request - Invitation
Quota - Invitation
Record - Invitation
Resolution - Issue
Delegation Credential Request - Creating/updating a delegation record and issuing a credential are different effects. The caller must prove the active delegation authority; the new key must prove possession. Scope/expiry cannot exceed the accepted delegation.
- Issued
Credential - Land
Checkout Request - Land
Stack Request - Land
Thread Request - Landing
Assessment - Landing
Assessment Status - Why a requested assessment is absent, not a verdict permitting landing. An emitted status has a known nonzero state and a Requirement with a known kind and nonempty explanation. UNSPECIFIED/unknown/missing means unknown to readers; producers MUST NOT emit UNSPECIFIED as a reason to wait or land. State, explanation, subject and policy MUST NOT reveal hidden base/target identity or existence. Missing/forbidden targets keep identical RPC behavior.
- Landing
Record - Decoded executor-signed integration, plus the exact signed Thread operation. The decoded fields are display/index hints, not independent authority. Verify raw_signed_operation against an independently pinned executor and referenced source, policy, review and evidence originals before trusting a landing. A local equivalent is a signed local target-history landing record with the same bindings, produced by a locally trusted executor. Only disclose these fields when the reader can inspect the corresponding signed originals.
- Landing
Satisfaction - Language
Resolver Status - List
Paths Event - List
Paths Request - Finite, exact-revision leaf-path listing. No depth cap or Search tip restriction. See docs/alpha-v2/cleanup-lane.md for matching, bounds and disclosure rules. ListPaths per-method minimum budget: 3 items, 65536 frame bytes and 65536 snapshot bytes after clamping, checked before source selection/matching. Admitted leaf paths <= 16384 UTF-8 bytes, complete path events <= 32768 encoded bytes, echo/completion <= 8192 each, plus 1024 framing reserve. Enforce the path bound at source admission; incompatible preexisting sources have UNAVAILABLE coverage independent of matches. Never skip/truncate a path. Every nonempty window emits its first visible path and can make progress.
- List
Spools Request - Grant-reachable unary Spool listing for whoami and admin surfaces.
ObserveWorkspace remains the live composed workspace view; this RPC is the
bounded one-shot catalog of Spools reachable through the caller’s grants.
repos_onlykeeps content-bearing (repository/project) rows. - List
Spools Response - Listed
Spool - Mark
Notifications Read Request - Material
Retention - Materialize
Checkout Request - Member
Record - Mint
Root Attachment - Public association of a credential mint root with one exact owner authority state. This grants no operations: ordinary Biscuit checks remain mandatory. Canonical v1 fields follow tag order using fixed-width/length-prefixed encoding. Domain: “heddle-mint-root-attachment-v1”.
- Money
- Mutation
Receipt - Mutation
Response - Native
Genesis Authority V1 - Native
Genesis Witness V1 - Native
Public Proof Bundle V1 - Public closure for native history. No job/delegation/terminal manifest. Original bytes are embedded in payloads; all dependencies must resolve inside this carrier. Purpose 2 and 4 reuse their unchanged public native layouts. This is reference/signature evidence, never owner enrollment or disclosure.
- Notification
Digest Override - Notification
Event - Notification
Preferences - Stored settings and weft-owned read projections are distinct. The inbox is the record and never waits for an email digest. ObserveNotifications with include_preferences returns all these fields in the same preferences payload.
- Notification
Record - Notification
Rule - Per-channel stored selector. Empty kind or “*” matches all kinds; empty or “any” actor_origin matches both “human” and “agent”. CHANNEL_UNSPECIFIED matches all channels. Spool rules take precedence over account rules; within a scope exact kind > exact channel > exact origin, with first rule winning ties. IN_APP and PUSH are on/off only (IMMEDIATE or DISABLED). First reject unknown channels/deliveries and UNSPECIFIED delivery with INVALID_ARGUMENT / FIELD_INVALID. Next check the email lock: an email rule matching account_security or security_surface must be IMMEDIATE, regardless of origin or Spool. Attempts to disable or digest their email, including wildcard rules and public unsubscribe, are rejected with FAILED_PRECONDITION / POLICY_DENIED before any write. This lock takes precedence over the email-only DIGEST check: other DIGEST rules on non-email or wildcard channels are rejected with INVALID_ARGUMENT / FIELD_INVALID.
- OAuth
Proof - Object
Address - These are native v2 transfers, not envelopes carrying v1 Push/Pull requests. A signed opening binds exact v2 scope, operation, policy, inventory and resume context. Packs and indexes travel as bounded protobuf chunks under flow control.
- Observe
Analysis Request - Observe
Attention Request - Observe
Billing Request - Observe
Catalog Request - Observe
Checkouts Request - Observe
Collaboration Request - Observe
Identity Request - Observe
Integrations Request - Observe
Notifications Request - Observe
Operations Request - Observe
Options - Observe
Ownership Request - Observe
Pairing Request - Observe
Runs Request - Observe
Spool Request - Observe
Thread Request - Observe
Threads Request - Observe
Workspace Request - Open
Discussion Request - Operation
Event - Operation
Record - Operation
Ref - Typed operation identity. Same resource as OperationRecord.ref and existing RecordRef command inputs; links never confer permission to observe it.
- Operation
Subject - Extensible subject union. Absent/unknown case means unavailable, not a guess from the destination spool’s name or current remotes.
- Owner
Authorization Bundle - Owner
Capability - V1 canonicalization and signature remain unchanged. The alpha.5 format-2 timeline grant is a hard cut: reject it. For format_version=3, canonical_owner_capability_v3 uses the v1 field order and encodings, but every grant appends one presence byte after action (exactly 0x01) followed by scope fields 1..6. Byte fields are counted; credential_identity uses precisely the origin transcript’s tag (0x01 or 0x02) and counted IDs, not a protobuf serialization; class is u32be. The scope is included both with and without capability_id. The v3 capability_id is SHA-256( UTF8(“heddle-owner-capability-v3”) || canonical body without capability_id); its owner signature is Ed25519 over SHA-256 of that domain followed by the canonical body WITH capability_id. The v1 domain and body never change. Unknown fields and unsupported versions fail closed. A v3 chain is direct (parent_capability_id empty), has one signed capability and a single-block subject Biscuit bound to its exact subject key/kind/ID and grant. Its authority block has the v1 owner_subject, owner_capability, owner_validity facts plus exactly one owner_timeline_accept_server(“<spool_uuid_hex>”, “<path_hex>”, “<principal_uuid_hex>”, “<credential_id_hex>”, “<pop_sha256_hex>”, <class_u32>, “<thread_id_hex>”, “<origin_sha256_hex>”) OR owner_timeline_accept_offline(“<spool_uuid_hex>”, “<path_hex>”, “<principal_uuid_hex>”, “<issued_ancestor_credential_id_hex>”, “<terminal_revocation_id_hex>”, “<derivation_path_sha256_hex>”, “<pop_sha256_hex>”, <class_u32>, “<thread_id_hex>”, “<origin_sha256_hex>”) fact, selected exactly by the original credential_identity variant. IDs are lowercase raw-byte hex only inside this Biscuit fact; path_hex is the v1 u32-length-prefixed canonical path segments as lower-case hex. Reject extra facts, attenuation blocks, duplicate grants and any PURGE fact; this direct exact grant cannot be widened by a later block. The grant selector MUST equal the actual canonical Spool UUID/path and MUST have include_descendants=false. V1 PURGE verifiers reject v3 rather than treating this action as purge or ordinary spool-write authority.
- Owner
History - This local persistence wrapper is not served as clone-readiness evidence. PullReady carries SignedSpoolOwnerGenesis; after TOFU-pinning it, the client constructs this keyring from the verified root and state-tree transition entries. Loading it recomputes every id/hash and verifies the full chain; unknown versions, gaps, duplicate sequences, forks, owner-id mismatch, or capabilities for another spool fail closed. Portable proof of one exact owner-key state, including historical states used by resource transfers. Several states of the same owner may appear.
- Owner
KeyBinding - Self-asserted attachment of a root key to the stable owner UUID.
stable_owner_uuidis exactly 16 bytes and never changes.challenge_nonceis exactly 32 bytes, single-use, and scoped by the service to the authenticated principal and UUID. binding_epoch begins at one and increases monotonically. - Owner
KeyTransition - Owner
Registration - Owner
Root - Owner
State - Account authority and resource ownership are separate. A root can be established before a spool exists. A spool’s genesis/transfer chain refers to that authority without changing the resource identity.
- Owner
Transition Record - A persisted proposal is distinct from an accepted owner state. Its original signatures remain independently verifiable; version governs complete/veto.
- Owner
Transition Response - Submission durably records a proposal. A later distinct operation completes it after its signed veto window; retrying submission never commits it.
- Ownership
Event - Pack
Chunk - Pack
Extent - Page
Info - Page
Request - Pairing
Event - Pairing
Initiation Binding - Pairing
Record - Paper
Code KdfMaterial - Paper
Code Unlock - Passkey
Authority - Current owner authorization for a passkey to attach temporary Ed25519 mint keys. This certifies key lineage, not operations: Biscuit attenuation, resource audience and current revocation remain mandatory. It confers no independent owner/root-establishment authority. Canonical fields follow tag order using fixed-width/length-prefixed encoding; domain “heddle-passkey-authority-v1”.
- Passkey
Mint Delegation - Passkey
Mint Grant - Account-free request for one passkey to authorize a temporary Ed25519 mint key. Canonical v1 fields follow tag order using fixed-width/length-prefixed encoding. Domain: “heddle-passkey-mint-grant-v1”. The WebAuthn challenge is SHA-256(domain || canonical fields). Account and owner fields are deliberately absent and MUST be derived from PasskeyMintDelegation.authority.
- Passkey
Proof - Passkey
Record - Account-private passkey inventory, requested through ObserveIdentity. The certificate is public verification material; no credential private key or reusable assertion is returned. Device registration is a separate lifecycle.
- Passkey
Registration - Password
Challenge Metadata - Only returned for PASSWORD. Every handle without an active password setup (unknown, passkey-only, deleted, or disabled) gets indistinguishable public metadata: salt derived deterministically from a server secret and the canonical handle, with the same costs, KDF/version, and response shape. Challenge IDs/nonces remain fresh. The server binds the account internally, never via a handle-to-UUID value at begin. Creation is throttled; expiry <= 10 minutes.
- Password
Challenge Proof - Proof of the public password verifier only. This message is never accepted by CompleteAuthentication, an owner mutation, or a credential issuer. Ed25519 signs SHA-256(“heddle-password-proof-v1” || canonical transcript): challenge_id[32] || nonce[32] || caller_device_public_key[32] || u32be(operation_id UTF-8 byte length) || operation_id UTF-8 || i64be(expiry Unix seconds). No protobuf is signed. The server’s one-use challenge record binds the current envelope revision; it is returned only with the continuation after successful proof.
- Password
Device Admission - The owner signs this exact admission, independently of the password proof. Ed25519 signs SHA-256(“heddle-password-device-admission-v1” || u32be(format_version) || account_uuid[16] || challenge_id[32] || continuation_id[32] || caller_device_public_key[32] || owner_state_hash[32] || u64be(owner_sequence) || u32be(client_operation_id UTF-8 byte length) || client_operation_id UTF-8).
- Password
Owner Envelope V1 - Encrypted 32-byte Ed25519 owner seed. The server stores and returns these opaque bytes, never a password, KEK, auth seed, or decrypted owner seed. Reject unknown versions/KDFs before use. Discard unknown protobuf fields and persist only the canonical re-encoding of known fields (<= 4096 bytes). AES-GCM AAD is ASCII(“heddle-owner-wrap-aad-v1”) || 0x00 || u32be(version) || account_uuid || owner_public_key || owner_id || u32be(kdf_id) || u32be(memory_kib) || u32be(iterations) || u32be(parallelism) || wrap_salt.
- Password
Owner Setup - Public authentication metadata, stored separately from the encrypted seed. Client input is UTF8(NFC(password)), preserving case and all spaces. Client guidance is 15+ Unicode characters and at most 1024 UTF-8 bytes; the server cannot enforce strength without seeing the password. The independent inputs are UTF8(“heddle-password-auth-v1”) || 0x00 || UTF8(NFC(password)) with auth_salt, and UTF8(“heddle-owner-wrap-v1”) || 0x00 || UTF8(NFC(password)) with wrap_salt. Both use the recorded Argon2id costs and 32-byte output. Only the Ed25519 public key derived from auth_seed crosses the network. Discard unknown fields, including nested envelope fields, and persist only the canonical re-encoding of known fields (<= 4608 bytes). The verifier and owner keys MUST be canonical, decompressible, and non-small-order. Ed25519 signatures use strict verification: canonical R and S, non-small-order points, and the standard group equation. Rust uses verify_strict; WebCrypto callers MUST precheck these conditions before its verify operation.
- Password
Owner Setup Authorization - Owner authorization for changing the password envelope. The owner signs SHA-256(“heddle-password-owner-setup-change-v1” || u32be(format_version) || u32be(action) || account_uuid[16] || owner_state_hash[32] || u64be(expected_revision) || setup_sha256[32] || u32be(client_operation_id UTF-8 byte length) || client_operation_id || i64be(expires_at Unix seconds)). expires_at has zero nanos and is future, with a bounded lifetime of at most 10 minutes from issuance. setup_sha256 is SHA-256 of the fixed-order v1 setup fields (the envelope’s fields in tag order, followed by auth_salt, verifier key, auth costs, auth_kdf_id and format_version; the possession signature is excluded), with byte fields raw and integers big-endian. DELETE uses 32 zero bytes. The current active account UUID, owner public key and owner ID MUST equal the setup envelope fields. Both actions CAS the account-lifetime revision. A successful PUT or DELETE atomically increments it and invalidates every outstanding password challenge and continuation. DELETE retains a tombstone revision; re-setup CASes against that value. Revision 0 is allowed only when no password setup has ever existed for this account; no revision is reused.
- Password
Unlock Completion - Password
Unlock Continuation - One-use delivery receipt, never a session, bearer, owner authorization or Biscuit. The continuation is bound to the challenge, revision, account and caller device, expires with the challenge, and is consumed at completion.
- Pinned
Source Target Revision - Platform
Authorization Request - The caller comes only from the verified credential and request PoP.
- Platform
Authorization Response - Point-in-time online decision for this RPC and the observing credential only. Never a portable grant, bearer, offline proof or reusable permit. Clients must call the matching check within each request before any side effect; missing or unknown advice denies. The check itself does not execute that side effect. Authorization comes only from current durable platform staff standing for a directly authenticated human across supported rooting tiers. Delegated, agent, service and anonymous credentials are denied. Verified credential and delegation attribution establishes directness, never a claimed account UUID, token staff fact or member-held action. Uncertain authorization state denies.
- Prepare
Account Claim Request - Device-local consent for claiming an agent-rooted human account. Browser possession and the explicit claim authorization are both required. Weft independently verifies the registration; the device never submits it.
- Prepare
Account Claim Response - Prepare
Custodial Recover Request - Prepare
Custodial Recover Response - Prepare
Import JobRequest - Prepare
Import JobResponse - Presence
Event - Presence session fan-out events for Track B
/presence/ws. - Principal
Record - Principal
Ref - Promote
Spool Request - Move a personal-root child to the account’s root-level address at its current slug. UUID, genesis, descendants, and direct grants survive. Bound by the destination ancestry’s effective max_audience: refuse promotion that would place a too-wide child under a tighter destination. Birth-parent lock does not follow the promoted spool.
- Proposed
Human Action - Prove
Password Unlock Request - Provenance
Read - Provenance
Result - Provider
Assembly Record - One record in output-pack order. Provider bytes must occupy an exact tiled physical range; inline bytes arrive as bounded ProviderInlineChunk frames. In either case the client verifies the encoded bytes and decoded object.
- Provider
Challenge - Provider
Connection - Provider
Consent - Provider
Dial Route - Authenticated transport hints only. The connected Iroh peer must still match provider.public_key; a URL is never a source of authority.
- Provider
Extent - Provider
Extent Event - Provider
Inline Chunk - Provider
Inline Source - Provider
Offer - Provider
Offer Extent - Capability-free candidate layout. It is not a serving grant. The client consents to its exact challenge before the issuer publishes ticket-bearing ProviderPlan; both phases use the same canonical layout commitments.
- Provider
Pack Location - Trusted issuer-to-provider control-plane registration. Never sent over the client Fetch stream. object_key names a private provider bucket object and must not appear in a client-visible ProviderPlan or ReadProviderExtent.
- Provider
Physical Range - A physical R2 range exactly tiled by independently hashed encoded records. record_set_commitment is a metadata commitment over pack identity, offset, length and ordered encoded record digests; it is not a hash of range bytes.
- Provider
Plan - Provider
Plan Challenge - An unsigned challenge carried over an already authenticated Fetch stream. Only the client’s exact-plan consent is signed. Both digests and the selected Thread/revision bind all tickets and virtual-pack placement.
- Provider
Plan Registration - Provider
Plan Registration Receipt - Provider
Range Chunk - Provider
Range Source - Provider
Read Ticket - The provider verifies this typed ticket against the published canonical extent set and the attenuated caller capability. A ticket alone grants no access; the opening’s native request proof binds the bearer key, the authenticated Iroh client peer matches client, and the receiver’s endpoint matches provider. Root rotation and expiry are independently checked.
- Provider
Ref - Provider
Refs Request - Provider
Repository - Provider
Result - Provision
Account Request - Invite-gated creation of an unclaimed human account. The independent root
slot stays empty. The agent proves its own key over this exact request using
principal:device-key:
; a human bearer cannot replace that proof. Existing key-bound accounts may be reused without an invitation. Reusing an operation ID with different bytes is rejected. - Provision
Account Response - Public
Handle Record - Public directory metadata contains no stable subject/account identifiers. ResolveResources supplies those only within an authorized resource scope.
- Public
Owner - A display label for a publicly visible account. Neither field grants access or supplies an owner verification key.
- Public
Principal Summary - Public presentation only; never carries credential, account settings or rights.
- Publication
Receipt - Publish
Content Client Frame - Publish
Content Finish - Publish
Content Open - Bulk content availability for an already admitted Thread capture. Metadata replication owns causal heads; uploading bytes cannot select or replace one. The opening PoP binds the exact Thread/revision, policy, complete pack/index addresses and lengths, operation identity, and any resume checkpoint.
- Publish
Content Server Frame - Purge
Operation Signing Body - Protobuf serialization is never signed. canonical_purge_operation_v2 is: u32_be(format_version), raw 16-byte spool_uuid, blob_hash as a u32-length- prefixed string, raw 32-byte payload_sha256, raw 32-byte leaf_capability_id. The leaf subject signs SHA-256(“heddle-purge-operation-v2” || canonical_body). The verifier binds this body to the actual spool, payload and direct PURGE grant. Moving the RPC package does not change this durable signing format.
- Purge
Sidecar Identity - PutApproval
Group Request - PutContext
Request - PutDelegation
Request - PutGrant
Request - PutPassword
Owner Setup Request - PutRecovery
Policy Request - PutReview
Policy Request - PutRun
Policy Request - Read
Artifact Request - Read
Budget - One budget vocabulary for observations, finite reads and transfer openings. For each field, zero chooses the advertised positive default; otherwise the effective value is min(requested, advertised maximum, current capacity). Above-maximum values MUST clamp, never cause rejection on that basis alone. Every endpoint (including devices/providers) MUST advertise maxima >= GUARANTEED_READ_BUDGET: 1024 items, 524288 frame bytes, 4194304 snapshot bytes. Effective fields MUST be >= min(resolved request, that floor). If capacity cannot meet this lower bound, fail retryably (UNAVAILABLE), never accept less. Reject only structurally impossible budgets from request shape, e.g. nonzero max_frame_bytes < 1024, snapshot bytes < frame bytes, or fixed selection overhead > max_items (INVALID_ARGUMENT), including per-method minima/reserves. Indivisible-result progress is guaranteed only for ListPaths and the four code-navigation methods, with explicit bounds/minima in cleanup-lane.md and code-navigation.md. Check minima before matching and bounds at admission. These methods return bounded PARTIAL/continuation for larger collections; their first visible row fits and unary results fit atomically. Other uncovered indivisible results, including ObserveRuns run/policy/timeline payloads, may not fit. After authorization/projection, if a whole record plus required controls cannot fit an empty legal batch, or a mandatory initial set cannot fit its snapshot, terminate before emitting/committing it with the existing CallFailure: RESOURCE_EXHAUSTED, message exactly “indivisible result exceeds read budget”, no ErrorDetail or retry hint. Reserve/charge one item and 128 bytes including framing for that failure per snapshot/batch; insufficient fixed overhead is INVALID_ARGUMENT before matching. If only the current batch is full, continue in a fresh bounded batch instead. Discard uncommitted staging; retain the last committed cursor. Never truncate, omit mandatory data, widen budgets or loop PARTIAL/Reset for a record that cannot fit. Do not automatically retry with the same budget. See streams.md. Existing blob chunks remain chunked; there is no generic chunk protocol.
- Read
Content Request - Read
Provider Extent Request - Record
Evidence Request - Record
Interaction Request - Record
Ref - Record
Review Request - Record
Signature - Recover
Checkout Request - Recovery
Argon2id Params - Recovery
Attempt - Recovery
Guardian - Recovery
Policy - The owner precommits to a threshold over distinct dedicated guardian keys. Product policy defaults to threshold >= 2 and a device-independent co-factor whenever Weft is a guardian. A 1-of-1 Weft policy is custodial and is allowed only after the client obtains the separately reviewed explicit confirmation.
- Redeem
Invitation Request - Redeem
Signup Invitation Request - A held shareable invitation code selects the admission directly; no lookup RPC, account bearer or device root is needed before choosing a passkey.
- Redeem
Signup Invitation Response - Refresh
Checkout Request - Register
Root Attachment Request - Register
Timeline Origin Request - Optional pre-expiry registration of an unchanged origin endorsement. Before the handler, middleware verifies a fresh method-bound Tier-1 proof. The caller must be an enrolled independent device root or active paired_credentials receiver_kind=device, with a persisted enrollment/pairing proof for its account, endpoint and proof key. Its authenticated effective uploader key MUST equal origin.uploader_device_public_key. In the write transaction, recheck its live credential, revocation, exact Thread/Spool writer authority, sharing destination/facet, billing and deletion gates. For a NEW registration, the complete origin chain must be presented, verified, live, unrevoked and unexpired at that transaction; a client timestamp cannot date itself. Under (uploader account, client_operation_id), store registration_digest = SHA-256(UTF8(“heddle-timeline-registration-v1”) || 0x00 || counted(client_operation_id) || counted(spool UUID) || counted(ThreadId) || counted(run ID) || counted(origin_sha256)), where counted is u32be length plus exact bytes, UUIDs are canonical lowercase 36-byte ASCII, and origin_sha256 includes the complete signed endorsement. The presented chain and transport PoP are authorization evidence excluded from this digest. Store the original server transaction timestamp, verified identity, chain binding and full revocation set beside the digest. A different digest for the same operation ID conflicts. An identical retry with a FRESH transport proof returns the original registered_at and digest, even after origin expiry, without re-dating or re-registering; it still checks current uploader, sharing, deletion and billing gates. Revocation of the issued ancestor or any Biscuit block invalidates the registered admission basis immediately. Registration never overrides revocation and never authorizes a later range by itself once the original has been revoked; fresh acceptance is then required.
- Register
Timeline Origin Response - Registration
Challenge - Registration
Recovery Policy - Release
Checkout Writer Request - Remote
Link Record - Removal
- Remove
Handle Request - Removes an active verified claimed handle belonging to the caller’s account. Weft MUST refuse removing the primary or last active claimed handle with CALL_FAILURE_CODE_FAILED_PRECONDITION / ERROR_REASON_LIFECYCLE_STATE. Select another primary first. Removing a handle never changes account UUIDs or revokes a credential; existing directory/tombstone policy still applies.
- Remove
Handle Response - Remove
Passkey Request - Retires the exact account-owned passkey. Same request PoP, caller ownership, exact-method caveats, idempotency and version CAS as RenamePasskey, plus the existing require_independent_root predicate: root_established plus an unattenuated credential. Delegated and ephemeral credentials MUST be denied. Weft MUST atomically refuse removal of the account’s last usable sign-in method with typed CALL_FAILURE_CODE_FAILED_PRECONDITION / ERROR_REASON_LIFECYCLE_STATE. Recovery factors alone are not usable sign-in methods. Retire sign-in authority and revoke temporary sessions minted by this passkey together; retain signed evidence for admitted history. Device-root cascades follow the canonical identity model’s CURRENT/TARGET revocation policy.
- Remove
Passkey Response - Remove
Spool Mount Request - Rename
Passkey Request - Renames an account-owned passkey without changing its credential, owner, sign-in authority, or owner-signed PasskeyAuthority. A successful rename changes only the stored label and advances the passkey record version.
- Rename
Passkey Response - Rename
Thread Request - Renew
Ephemeral Session Request - Renews a short-TTL ephemeral (declined-enrollment) session in place. The renewal is proven by the caller’s existing ephemeral bearer plus a request PoP signed by the ephemeral key (CallContext.request_proof), so the body carries no session ref: the renewed session is exactly the caller’s own.
- Renew
Ephemeral Session Response - Reopen
Discussion Request - Reopening a blocking discussion obeys the same inherited rule as resolving; non-blocking discussions retain ordinary writer authorization.
- Replicate
Thread Request - Replicate
Thread Response - Replication
Have - Replication
Need - Replication
Open - Replication
Operations - Replication
Ready - budget is the mandatory effective ReadBudget echo under stream.proto rules.
- Replication
Receipt - Replication
Rejection - Request
Held Handle Request - Request
Held Handle Response - Requirement
- Resolve
Checkout Request - Resolve
Discussion Request - Resolve
Handles Request - Resolve
Handles Response - Resolve
Import Source Request - Authenticated bounded discovery for BOTH connected and public HTTPS sources. Public: no connection/installation, private=false, repository ID equals URL (or is empty on input). Connected: current caller-owned GitHub connection, exact repository and installation grant. Host applies URL/SSRF and redirect checks before any fetch; discovery never enrolls or stores credentials. Accept the selected identity exactly or refuse: connection, repository ID, installation, visibility and clone_url must match the result. Public empty repository ID may only be completed to the exact requested clone_url. Validate canonical HTTPS; never normalize. repo and repo.git are distinct. Redirects are host-controlled transport only and never redefine the selected or signed URL/custody. A different resolved identity is refused, not adopted.
- Resolve
Import Source Response - Resolve
Invitation Request - Public capability preview. The invitation ID alone reveals nothing; the redemption secret is passed in the request body and never placed in a URL path or query. Invitation links get forwarded: any holder of the secret can see the spool address (including path segments) and name, role, expiry, inviter’s public handle and display name, and the delegated agent’s display label when present. The inviter’s handle also reveals that this person administers the spool, even if the spool is private. No recipient email is disclosed. The inviter lookup MUST use the same query shape for every status so timing does not reveal invitation validity.
- Resolve
Ownership Conflict Request - The original local owner chooses the winning account; that account’s currently authorized owner or delegate accepts. Neither arrival order nor a claimant’s signature alone adjudicates the conflict. Never implicit in upload/enrollment.
- Resolve
Resources Request - Resolve
Resources Response - Resolve
Signup Invitation Request - Resolved
Alternative - A former source head resolved by a later capture. Producer and resolver retain the State’s claimed actor labels and their attribution assurance; authenticated IDs remain subject to CaptureSummary’s proof requirements.
- Resource
Ownership Transfer - Complete client-authored transfer. Missing either signature fails closed.
- Resource
Resolution - Resource
Selector - Account names and paths resolve to stable resources once. They never become authorization roots or replace the stable IDs in subsequent commands.
- Resource
Transfer Acceptance - Resource
Transfer Audit Record - Append-only result committed atomically with the resource-to-owner re-anchor. audit_record_hash is SHA-256(“heddle-resource-transfer-audit-v1” || the canonical transfer, commit time, and previous audit hash).
- Resource
Transfer Handoff - Canonical source offer for an atomic resource ownership re-anchor. canonical_resource_transfer_handoff_v1 encodes fields 1 through 8 in field order using fixed-width big-endian integers and length-prefixed byte strings. UUIDs are exactly 16 bytes, state hashes and nonce are exactly 32 bytes.
- Resume
Subscription Request - Retry
Import Source Request - Retry an incomplete terminal FAILED/CANCELED physical attempt into its original Thread. The original operation remains immutable; this command creates a new operation and never creates a second Spool or Thread genesis. Allocate a fresh host-generated physical UUID, distinct from ALL prior attempts and independent of client_operation_id. Return receipt.pending_operation for it under this request’s ID. Persist allocation, retry_of/superseded_by links and the exact receipt together; exact frozen replay returns that receipt. Changed bytes under the same ID -> OPERATION_ID_REUSED, before current CAS checks. Bind the writer-only job-state eligible target, destination/job/lineage, operation CAS and active authority in one admission transaction. CONNECTED requires caller ownership of the exact retained connection, current exact grants and selected-commit availability. Bind subsequent fetches to that authorized attempt; never select credentials from the old initiator. Public-git permits any current writer subject to signed authority/all checks.
- Review
Comparison - Exact comparison resolved within a review-section snapshot. A client submits these source/base/policy bytes when recording a decision; a Thread’s genesis base and an arbitrary source head are not substitutes for this binding.
- Review
Coverage - Review
Decision - Review
Policy Record - Review
Record - The observed decision and the exact portable signed control that authored it.
- Review
Symbol Anchor - Review
Symbols - Revise
Intent Request - Revise
Spool Request - Compare and replace display name and patch selected settings atomically. The stable UUID, parent, and immutable owner genesis are unchanged. Owner signature is not a prerequisite. The mere existence of a signed-policy tip does not block this RPC (independent CAS from expected_head). settings.audience / default_state_audience are bounded by the standing inherited max_audience (this spool and ancestors). Exceeding it is PERMISSION_DENIED.
- Revision
Ref - Revoke
Delegation Request - Revoke
Device Request - Revoke
Grant Request - Revoke
Invitation Request - Revoke
Provider Connection Request - Revoke
Session Request - Root
Attachment - User-root proof is portable. Account association records Weft’s acceptance of an already user-authorized key; it is not the source of that key’s authority.
- Root
Attachment Binding - Portable binding of a proved delegated key to its Iroh endpoint. Authority remains the Biscuit’s complete attenuation chain, not this locator binding. SignedRecord format heddle.root-attachment.v2 carries canonical bytes signed by both endpoint and subject (one signature when the keys are equal). The shared verifier requires a locally trusted root, verifies the Biscuit’s effective proof key and limits, then verifies digest, time and endpoint.
- RunArtifact
- RunEvent
- Each run, policy and timeline payload is a whole indivisible record. Bounded continuation cannot split it; the ReadBudget bounded-failure rule applies.
- RunPermission
- RunPolicy
- RunRecord
- Satisfied
Policy Requirement - Search
Domain Status - Per-domain readiness is independent of result count and hidden matches. An unavailable index is not represented as an empty, complete result set.
- Search
Event - Search
Hit - Search
Request - Section
Replacement - Section
Status - Semantic
Closure Object - Semantic
Index Artifact - Self-contained derived index, readable in one bounded artifact stream. Nodes are unique and sorted by hash; root_hash is 32 bytes and must name an included root. All derived root/tree/file nodes are included and verified. Opaque file entries may identify source commitments, but their raw source bytes are never included. Parsed/opaque counts describe this exact source.
- Semantic
Index Limits - Hard ingestion ceilings, independently of general source-transfer budgets. Absent on Ready means client SemanticIndex ingestion is unsupported. A supporting endpoint advertises positive limits no greater than 100000 nodes, 67108864 decoded bytes and depth 64. See code-navigation.md for accounting.
- Semantic
Index Object - One existing Heddle semantic root/file/directory object. The canonical bytes use the versioned Heddle semantic index codec. The 32-byte hash uses Heddle’s Blob identity: BLAKE3(UTF8(“blob”) || uint64_le(canonical.length) || 0x00 || canonical), matching Blob::hash(). Hashing canonical alone is incorrect. This object grants no right to fetch other CAS objects.
- Semantic
Index Publication - Signed opening inventory for one client-attested native StateAttachment. At most one index for this exact opening Thread/revision. Original attachment bytes travel in TransferSidecar; all semantic object bytes travel in the declared native pack/index pair. The complete transitive closure includes binding-delta parents, edge target file nodes and reverse dependencies.
- Session
Record - SetAttention
State Request - SetBookmark
Request - SetDisplay
Name Request - SetDisplay
Name Response - SetNotification
Preferences Request - Atomic settings replacement under expected_version. Read-only projection fields (effective_delivery and next_digest_at, including overrides) are ignored and recomputed, never persisted or used as authority. The server MUST validate every rule and digest interval before writing; invalid delivery or cadence rejects the whole request. Portable helpers complement remaining host validation of timezone, selectors, duplicate overrides and input budgets.
- SetPrimary
Handle Request - Only an active, verified claimed handle belonging to the caller’s account can become primary. Held names and unverified claims are not eligible.
- SetPrimary
Handle Response - SetRemote
Link Request - SetSpool
Mount Request - SetSupport
Access Request - SetThread
Audience Request - SetThread
Retention Request - SetThread
Sharing Request - Sharing
Destination - Sidecar
Authorization - Portable authorization for an exact purge, independently of its transport.
- Sign
Account Claim Request - Sign
Account Claim Response - Signed
Delegated Import Operation V1 - Signed
Import Genesis Authority V1 - Signed
Import JobDelegation V1 - Signed
Import Member Permission V1 - Signed
Mint Root Attachment - Portable owner -> passkey -> temporary mint-key authorization. This v2 shape is the only SignedMintRootAttachment accepted for passkey sign-in.
- Signed
Native Genesis Authority V1 - Signed
Owner Capability - Signed
Owner KeyTransition - Authorizations sign canonical_owner_key_transition_v1(transition).
- Signed
Owner Mint Root Attachment - Owner-signed account-bound attachment retained for registration of a durable independent mint root. Passkey authentication never accepts this shape: its account-free grant and owner-certified passkey chain use SignedMintRootAttachment below.
- Signed
Owner Root - Signed
Passkey Authority - Signed
Password Device Admission - Signed
Password Owner Setup Authorization - Signed
Policy Body - Signed
Policy Head - CAS predecessor. Independent of ReviseSpool.expected_version. Zero hash + sequence 0 = genesis.
- Signed
Policy Merge Rule - Signed
Record - A durable, versioned record. Its format defines canonical bytes, domain, signature algorithm, bounds and verifier. Generic protobuf serialization is never the signing input. Unknown critical formats fail closed.
- Signed
Resource Transfer Handoff - Signed
Spool Owner Genesis - Self-signed genesis evidence. owner_signature.signer_key_id MUST identify genesis.owner_public_key, and that key signs the exact 32-byte digest:
- Signed
Spool Policy - Offline-verifiable, owner-gated payload. NOT a copy of SpoolSettings. Substantive content: grow-only revocations + max_audience ceiling.
- Signed
Spool Policy Record - Signup
Invitation - Signup
Invitation Resolution - Signup
Reservation - Skipped
Import Ref - Source
Anchor - Source
Conflict Candidate - Source
Conflict Set - A bounded set of immutable source alternatives observed at one checkout version. Candidate IDs are opaque and only meaningful within this version.
- Source
Location - Exact current coordinates, never an authoring input or a replacement for the original evidence in SourceAnchor. No implicit tracking from these fields.
- Source
Operation Frontier - Source
Target Reference - Shared by primary anchors and annotation references. This is a reference, never a grant to read the target’s source or its owning Thread.
- Source
Target Resolution - Source
Target Resolution Event - Shared map updates for anchors and tags. Snapshot/Upsert frames carry upsert; Remove frames carry remove. Deduplicate by key within a checkpoint batch. Maps clear with Thread collaboration / Spool context section replacement and replacement snapshots. Remove the entry when its last referrer leaves the observed window. Neither missing targets nor these events grant source access.
- Source
Target Resolution Key - Stable within an endpoint observation. Only a viewed_thread binding requires viewed_thread here; named and pinned bindings MUST omit it. The selected revision is a value, so capture moves one shared entry, not every referrer.
- Source
Target View - Exact view selection for a Thread’s inherited target bindings. This selects resolution only; it grants no source access and does not select more records.
- Spool
Address - Observed address of a stable Spool identity. Renames change the address, never the UUID. An address is presentation/routing metadata, not authority.
- Spool
Capability Grant - Spool
Creation Proof - Spool
Creation Statement - A creator’s statement of exact intended creation. created_at is NOT an admission timestamp. Only actual current admission or independently retained accepted evidence establishes whether this creation was permitted then. Canonical v1 fields follow tag order; domain “heddle-spool-creation-v1”.
- Spool
Event - Spool
Mount - Spool
Mutation Response - Committed overview and independently verifiable owner history seed the caller’s view directly. The receipt is not a trust root or a TOFU pin.
- Spool
Overview - Spool
Owner Genesis - Immutable owner-key binding created with a spool.
spool_uuidis the raw 16-byte UUIDv7 that is also the spool id.owner_public_keyis the owner authority key at creation; no registry key or nonce participates. - Spool
Pages - Spool
Ref - Spool
Selector - Spool
Settings - Fresh bootstrap permits child creation and has no implicit approval mandate. Explicit review policies still apply. ReviseSpool patches selected settings; its settings participate in the observed review policy version.
- Stack
Landing - Each source is the exact revision supplied by the caller. For every distinct target, expected_target is compared once against the initial transaction snapshot. Ordered members then integrate into that target’s evolving frontier.
- Start
Analysis Request - Start
Thread Request - State
Read - Exact immutable source summary. Authored sidecars (including risk signals, conflict resolutions and semantic attachment attribution) are not source objects: use audience-checked Thread, checkout and Analysis projections. The selection emits one StateSummary followed by selection_complete.
- Store
Provider Credential Request - Stream
Checkpoint - Stream
Complete - Stream
Data - Stream
Frame - Stream
Heartbeat - Stream
Open - Stream
Reset - Submit
Custodial Recover Request - Submit
Custodial Recover Response - Submit
Owner Capability Request - Submit
Owner Transition Request - Submit
Recovery Proof Request - Submit
Recovery Proof Response - Submit
Signed Policy Request - Owner-signed spool policy submit. Not a prerequisite of ReviseSpool. request.spool MUST equal record.body.spool_uuid; mismatch fails closed. Proposed max_audience, if present and specified, MUST be <= the ancestors’ effective ceiling (min over ancestors only). Retry by client_operation_id. The biscuit RESOURCE_OWNER role is necessary but not sufficient: the verifier checks the owner signature against the server-derived current owner OwnerState. Receipt binds SignedPolicyHead (Decision 8).
- Submit
Signed Policy Response - Support
Access Record - Synchronize
Remote Request - Thread
Alternative - Thread
Audience Policy - Thread
Control Authority - Original author evidence bound into each signed Thread metadata operation. Supplied history never establishes trust: receivers verify against separately admitted current account authority at first durable admission. Canonical protobuf encoding is mandatory and the entire envelope is bounded to 64 KiB.
- Thread
Event - One typed stream composes a Thread’s decision context. Common frame controls have no payload. Every data frame carries exactly one payload; snapshots and delta batches become visible only at their checkpoint. SectionReplacement.section and SectionStatus.section use these exact keys: overview (overview); captures (capture); review (comparison, review, diff); evidence (evidence, check_acknowledgement); resolved_alternatives (resolved_alternative); collaboration (discussion, turn, context, source_target); analysis (analysis); checkouts (checkout); timeline (timeline_event, run, operation); sharing (sharing, publication). Replacement clears only that section’s committed collection. V1 timeline “operation” is explicitly empty. Timeline always reports a section status, including an eligible empty collection. Timeline run/event frames reuse RunRecord/TimelineRecord output, ordered by server change sequence; recorded_at is display time only. Removal uses Removal. A lost timeline membership proof or change-log continuity ends with Reset then FIN. Resource-reader and Thread/Spool audience rights are ceilings. A run/event is visible only to its verified direct-human principal account or a live same-principal agent whose final effective PoP key digest exactly equals the run’s frozen actor digest. Agent labels, Thread/Spool owner and admin roles never override that predicate. Join current sharing epoch, audience, billing/deletion gates and the payload deadline before order, limit or count. Forbidden and absent run IDs, pages and cursors have identical status, count, cursor and Reset shapes. No hidden append advances a visible cursor. Every eligibility-bearing frame gets a fresh current database authorization check immediately before handoff; expiry wakes idle followers without a sweep. Unknown section semantics require a fresh supported view, never silent loss.
- Thread
Genesis Record - Carries original ownership proof with the immutable creator-signed identity. The receiver independently verifies it; transport credentials never select the owning account or enroll an otherwise-untrusted account root.
- Thread
Id - Thread
Intent - Thread
Invitee - Thread
List Event - Thread
Metadata Conflict - Thread
Mutation Response - Thread
Name Selector - Thread
Overview - Thread
Ownership - Thread
Ownership Conflict - Thread
Pages - Independent section windows share one observation’s total read budget. Missing windows select bounded defaults only for requested sections.
- Thread
Property Frontier - Thread
Query - Thread
Ref - Thread
Relationship - Thread
Retention Policy - Thread
Sharing Policy - Timeline
Acceptance Scope - V3 grant scope. This names the ORIGINAL credential, not the accepting subject key or an agent display label. All fields are mandatory and exact.
- Timeline
Admission Acceptance - A current direct-human run-principal authority or a current format-3
OwnerAuthorizationBundle (owner_records.proto) with an
ACCEPT_TIMELINE_ORIGIN grant signs this exact acceptance:
UTF8(“heddle-timeline-run-acceptance-v1”) || 0x00 followed by fields 1..6
below, then one authority byte (1 for principal credential, 2 for owner
capability) and counted(exact authority bytes). Byte fields use
u32be(length)||bytes, uint64 fields use u64be, and event_count uses u32be.
The signature and transport PoP are excluded. The original digest is
SHA-256 of the origin transcript plus
its 64-byte signature. The request digest is SHA-256 of:
UTF8(“heddle-timeline-upload-v1”) || 0x00 || counted(client_operation_id)
|| counted(spool UUID) || counted(ThreadId.value) || counted(run ID)
|| u32be(canonicalization_version) || u64be(run_revision)
|| one byte snapshot presence || [u32be(state)||counted(harness) if present]
|| u32be(event count), then for each event in wire order:
u64be(position)||u32be(kind)||i64be(recorded_at.seconds)
||u32be(recorded_at.nanos)||one byte tool presence
|| [u32be(tool) if present]
|| counted(origin SHA-256) || u64be(first_position).
countedmeans u32be(byte_length)||exact bytes; presence is 0 or 1. The acceptance, its authority selector and transport PoP are excluded. Unknown fields are invalid. This layout is independent of protobuf serialization. An acceptance is valid only for this exact digest and position range. For principal_credential_id, Weft resolves the exact ID in its current credential registry, verifies a live independent root or server-issued direct-human session/pairing chain, and uses that chain’s final effective Ed25519 PoP key for this signature. Its account MUST be the origin’s verified principal. Agent labels, account claims and uploader credentials do not confer acceptance permission. For owner_derived_capability, the bytes are a protobuf wire encoding of OwnerAuthorizationBundle, at most 65536 bytes (64 KiB). Decode the complete bundle, rejecting unknown fields and trailing bytes. Verify its owner root and transition history against the independently pinned CURRENT owner state of the run-principal account; OwnerRoot.account_uuid MUST equal the verified principal UUID (never accept a state supplied only by this bundle). Then verify the single format-3 capability and subject Biscuit. The grant’s exact Spool selector, Thread ID, original principal UUID, credential class, original credential identity variant and values, effective key digest and signed origin SHA-256 MUST equal the verified origin. The leaf CapabilityPrincipal.key is the effective Ed25519 signing key for this acceptance. SignedOwnerCapability.signature signer_key_id instead resolves to the owner issuer key through the accepted owner transition at issuer_state_hash and its live rotation/recovery signing window; reject an obsolete, vetoed or uncommitted issuer state. The subject signs this acceptance transcript with its effective key, not the owner key or the uploader key. Recheck capability validity interval, direct-only/single-block attenuation restriction, active owner transitions/recovery windows, every credential and capability revocation, and the subject proof at the admission transaction. No v1 PURGE grant, generic grant envelope, passkey certificate alone, or owner/admin status authorizes acceptance. The acceptance bytes do not replace the uploader’s independent Tier-1 transport proof. - Timeline
Offline Derived Credential - Timeline
Origin Credential Identity - Exactly one credential identity. The selected route has no fallback.
- Timeline
Origin Endorsement - The active origin credential signs this exact transcript with Ed25519: UTF8(“heddle-timeline-run-origin-v3”) || 0x00, then, in field order below, each byte/string field as u32be(byte_length) || its exact bytes; class is one unsigned byte (1 or 2). Credential identity is one tag byte followed by counted IDs: 0x01 || counted(credential_id) for server_issued, or 0x02 || counted(issued_ancestor_credential_id) || counted(terminal_revocation_id) || counted(derivation_path_sha256) for offline_derived. UUIDs are 36 lowercase ASCII bytes in canonical hyphenated form. The signature itself is excluded. No protobuf serialization, client timestamp or hash of a reconstructed RunRecord is a signing input. For offline_derived, Weft verifies the COMPLETE chain from the exact named Weft-issued ancestor authority block through the terminal block, with at least one attenuation block. Every Biscuit block, including the authority, MUST use signature-v1. Each attenuation signature covers the preceding block signature. Reject any chain containing a signature-v0 block. Verify the complete chain, attenuation and lineage against the issued ancestor, then derive revocation IDs from every block in order, including the authority and terminal blocks. Each is the 64 raw signature bytes from Biscuit::revocation_identifiers(). Compute derivation_path_sha256 as SHA-256(UTF8(“heddle-timeline-derivation-path-v1”) || 0x00 || u32be(N) || ID[0] || … || ID[N-1]), where N >= 2 and IDs are exactly 64 bytes. Each signature-v1 attenuation block binds to its predecessor, and the complete ordered signature list commits to the entire path. Require the computed path digest and terminal ID to equal the signed identity; match SHA-256(final effective PoP public key) to the signed key digest, then verify the endorsement with that effective public key. The ancestor ID alone never authenticates the agent. Reject a wrong root, path, terminal ID or key. An exact pre-expiry registration may supply the stored VERIFIED chain binding and original effective public key when the chain is absent from an upload. Otherwise the complete chain is required, including with fresh acceptance or a receipt retry. Fresh acceptance may override original expiry or revocation only for ADMISSION; it never skips lineage, path/key recomputation, signature verification, or original public-key resolution. A live-chain admission requires the chain to be live, unexpired and unrevoked. Registration stores the full revocation set; later revocation invalidates its admission basis.
- Timeline
Record - Timeline
Server Issued Credential - Transfer
Checkpoint - Transfer
Object - Transfer
Ownership Request - Transfer
Ready - Transfer
Selection - Transfer
Sidecar - Tree
Read - Unsubscribe
Notifications Request - Public, single-purpose disabling action. The opaque capability determines the recipient and exact allowed selectors; no account credential is required. Each requested rule must select an authorized channel and DISABLED delivery.
- Update
Subscription Request - Upload
RunSummary - Dedicated upload summary: only the two allowlisted v1 fields.
- Upload
Scrubbed Timeline Ack - Upload
Scrubbed Timeline Request - One logical request for one Spool/Thread/run; encoded request <= 256 KiB. The full batch commits atomically. Every attempt needs a fresh method-bound Tier-1 PoP nonce/timestamp, including an identical retry. The authenticated uploader is an enrolled independent device root or active paired device as above, and its effective key must match the immutable origin uploader key. Under the Spool/Thread lock first admission enforces unique (spool_id,run_id) across ALL Threads and sharing epochs, and freezes the exact Thread, principal, actor class/effective key digest, uploader account/key and first sharing epoch. A different Thread or uploader cannot re-admit that run. Before accepting a new operation ID, check both the live run and durable keyed run fence across epochs. A purged run cannot be resurrected with a new operation ID, origin signature, or sharing re-enable. Retain the terminal operation digest fence and run HMAC fence after expiry, DISCARD or sharing purge, including runs with no policy deadline. Delete them with Thread/Spool deletion or relevant account/billing-lock deletion; the durable deletion fence then makes old attempts uniformly absent. A first upload requires a presented live origin chain at transaction time, an exact previously registered pre-expiry origin not since revoked, or fresh scoped acceptance of this request. For offline_derived, the complete verified chain MUST be presented unless that exact verified registration binding is available; acceptance never supplies provenance evidence. Later batches recheck the recorded admission basis and acceptance range, plus current uploader, sharing, billing, deletion, retention and revocation gates in the transaction.
- Upload
Scrubbed Timeline Response - Upload
Timeline Event - Dedicated event input; canonical encoded event size is at most 2048 bytes.
- Upload
Timeline Position Gap - Verified
Email Reservation - Verify
Evidence Request - Verify
Evidence Response - Veto
Custodial Recovery Request - Veto
Owner Transition Request - Veto
Recovery Request - Weft
Custody Recovery Policy Selection - The only supported custodial recovery shape is exactly one WEFT guardian with threshold one. It is never inferred from an omitted selection.
- Weft
Custody Warning Consent - Versioned evidence that the user saw and accepted the exact 1-of-1 Weft custody warning. warning_sha256 is SHA-256 of the reviewed UTF-8 warning text for warning_version; unknown versions and digests fail closed.
- Workspace
Event - Workspace
Pages
Enums§
- Account
Deletion Outcome - Analysis
Kind - Audience
- Existence/history audience for a spool. Numeric tags match v1 Visibility (PRIVATE=1, INTERNAL/MEMBERS=2, PUBLIC=3). Do not add AUDIENCE_INTERNAL.
- Authorization
KeyAlgorithm - Behavior
Correspondence Kind - Behavior
Limitation - Behavior
Match Reason - Behavior
Provenance - Behavior
Support - Billing
Interval - Blocking
Discussion Resolve Rule - Delegated blocking-discussion rule, inherited down the spool tree. The nearest non-UNSPECIFIED setting wins; an unset root defaults to ANY_WRITER, preserving existing behavior. This is not an owner-signed policy ceiling. Every permitted actor still needs ordinary write access. Non-blocking discussions are unchanged. Reopening a resolved blocking discussion and changing blocking to non-blocking obey the same rule as resolving it. Agents act as their person (including opener identity), within agent ceilings; an administrator role never bypasses those ceilings or OPENER_ONLY. Unknown values MUST be rejected rather than widening permission.
- Capability
- Stable semantic affordance, independent of RPC spelling. Never authority. Zero/unknown values mean unknown: do not infer permission or show an action.
- Capability
Principal Kind - Catalog
Sort - Public resource discovery never includes private grants, devices or account attention. Exact public content still uses the ordinary resource read APIs.
- Clone
Owner PinKind - Code
Edge Kind - Code
Navigation Reason - Code
Occurrence Role - Code
Symbol Kind - Coverage
- Credential
Kind - Credential
Method - Explicit ceremony selection; omitted or unsupported methods are rejected. Password unlocks a client-held owner key; OAuth retains its own ceremony. Neither a password verifier signature nor an OAuth proof is owner authority.
- Custodial
Recovery State - Discussion
Action Kind - Endpoint
Kind - Evidence
Currency - Handle
Kind - Hold
Lifecycle - Delegated HOLD-verdict lifecycle on SpoolSettings. Not abandoned_thread_retention. v1 VersionedHoldLifecycle was chain-inherited and offline-citable; moving HOLD here drops that citation. UNSPECIFIED inherits; the built-in root default is EXPLICIT_SUPERSESSION.
- Import
Authority Record Kind - Import
Delegation Purpose - Fixed field order, counted bytes, BE integers and domain-separated digests follow owner_records.proto, not protobuf serialization. See the normative contract and the ONE fixed Rust/TS fixture in tests/fixtures/.
- Import
GitHash Algorithm - Import
JobStatus - One snapshot for Cancel and Retry; public proofs travel through Fetch/export. Host custody/source associations remain durable admission inputs, not read fields.
- Import
Preparation Refusal Reason - Import
RefDisclosure - Signed acknowledgement of the fixed disclosure in the normative contract: the exact OID is unavailable; the branch may move before execution and the job will convert its then-observed commit. Never infer consent from an empty OID. A known OID MUST use PINNED_COMMIT, including after an attempted pin.
- Import
RefMode - Import
Retry Unavailable Reason - Import
Source Mode - Landing
Requirement Kind - Specific cause from a landing evaluator or a blocked LandThread/LandStack mutation receipt. Never infer it from explanation text. EVIDENCE_* pairs with Requirement.kind=EVIDENCE; REVIEW_* with REVIEW; REFRESH_* with REFRESH; POLICY_* with POLICY; CONFLICT_* with CONFLICT_RESOLUTION; and DISCUSSION_* with DISCUSSION. UNSPECIFIED is only a legacy/unknown cause, never evidence that landing is permitted. Do not report hidden record detail.
- Native
Genesis Owner Kind - Separate native contract; never selected because an import lacks delegation. Canonical layouts and producer order: docs/alpha-v2/native-host-witness.md.
- Native
Genesis Payload Kind - Explicit canonical purpose-1 discriminator. Import payloads have binding format_version=1 at this position; native payloads have this value=2.
- OAuth
Provider - Observation
Mode - Shared observation protocol. Each RPC has a typed event payload alongside StreamFrame. Only a data frame carries a payload. See docs/alpha-v2/streams.md. A logical RPC occupies one reliable, ordered Iroh stream; this contract does not turn protobuf frames into unreliable UDP datagrams.
- Owner
KeyBinding Kind - Owner
KeyTransition Kind - Provider
Repository Size Estimate State - Advisory Git storage estimate, never converted result bytes or authority.
- Recovery
Guardian Kind - Recovery-key provenance is part of the signed policy. A verifier can distinguish paper, social, and Weft guardians when counting signatures.
- Requirement
Kind - Resolution
Kind - Resource
Role - Review
Readiness - Rooting
Tier - Account onboarding state, never a substitute for a verified capability or owner-root binding. Promotions are explicit; a credential’s attenuation must survive promotion of its account. AGENT_ROOTED denotes an unclaimed human account with an empty independent-root slot, not an account owned by an agent.
- Search
Domain - Search
Match Kind - How this match was established; score is only comparable within this query.
- Search
Source History - Which accepted source revisions participate in content and symbol search. Content and symbol search index only the current source tips of each Thread (weft#2433); full-history search is planned (weft#2470).
- Seat
Pricing Mode - Section
Status Reason - A safe explanation for partial or unavailable section coverage. Reasons never grant access or disclose withheld content, identifiers, paths, or counts.
- Semantic
Attestation - Parse-free reads of an admitted client SemanticIndex. Every request requires the exact owning Thread and revision, with identical live source, audience, embargo and entry gates to ReadContent. See docs/alpha-v2/code-navigation.md. Hidden targets are indistinguishable from absent ones, including readiness, ambiguity, truncation, counts and page tokens. Never follow a spoollink. All four methods have per-method minimum budgets: 4 items, 65536 frame bytes, 65536 snapshot bytes after clamping. Reject smaller fields INVALID_ARGUMENT before index selection/matching. Admitted encoded sizes: CodeSymbol and CodeOccurrence <= 16384 each; CodeSemanticRef and CodeImporter <= 32768 each; CodeNavigationMetadata and PageInfo <= 8192 each. Reserve 1024 wrapper/control bytes. A whole definition pair or first paged row always fits. Enforce item and worst-case metadata bounds at admission; incompatible preexisting indexes are NO_INDEX independent of matches. See code-navigation.md for full rules.
- Session
State Filter - State filtering never expands the caller’s authorized session scope.
- Shared
Facet - Signed
Policy Merge Semantics - Source
Path Kind - Unknown, including a missing path at the exact revision. Never infer from extensions, line numbers, the working tree or the current Thread head.
- Source
Path Kind Source - Read-projection provenance, never part of a canonical signed source map.
- Spool
Capability Action - Spool
Section - Stream
Data Kind - Stream
Reset Reason - Subscription
Status - Provider IDs, API credentials and webhook secrets never appear in this contract. Weft resolves the authenticated account and checks the credential’s effective delegated billing authority for every read and mutation.
- Thread
Lifecycle - Thread
Property - Thread
Section - Timeline
Origin Credential Class - Timeline
Start - Selects where a single run’s timeline observation begins. This does not change the default oldest-first collection pagination.
- Upload
Timeline Event Kind - Upload
Timeline Tool - User
Verification