Allowed operations, denied operations, input limits, output shape, cost estimates, and evidence policy are named before trust.
LocalEndpoint guide
Schema index
Use the schema index as the source of truth for endpoint manifests, diagnostics, consent plans, and evidence packets.
Schema atlas
Contracts become inspectable before connection becomes possible.
LocalEndpoint schemas describe endpoint shape, evidence shape, readiness packets, and agent-readable metadata without turning any public document into runtime permission.
Redacted receipts and hash manifests let another person review what was checked without exposing private endpoint data.
Distribution evidence describes package identity, route declarations, and unsupported runtime behavior without deploying anything.
Search and agent guidance stay aligned with the public boundary: indexable metadata must not imply execution.
Endpoint contract compiler
A connection starts as a contract, not a socket.
The schema turns a local capability into inspectable intent: what it is for, what it may do, what it must refuse, what evidence it returns, and where human approval is required.
Visitors and agents see why an endpoint exists before any local handoff is considered.
Permitted actions, inputs, output shape, and rate limits are declared as fields.
Credentials, raw private data, hidden dispatch, and unlisted operations stay outside the contract.
Review artifacts describe what was checked and what the validation does not prove.
A valid manifest can prepare review, but it cannot authorize runtime work from the public site.
Private endpoint approval belongs to the local companion, not a website route.
Schema proof relay
Fields become proof steps before they become local decisions.
The schema page turns endpoint metadata into a review sequence: declare intent, narrow operations, validate shape in the browser, export evidence, then move approval to the local companion.
Identity, purpose, operation names, limits, and refusal rules make the endpoint legible before trust.
The browser can inspect the manifest against schemas without uploading private files or probing the device.
Hashes, findings, warnings, and non-claims travel as review artifacts instead of raw endpoint material.
The public website can prepare the question; private runtime authority stays with the person on the device.
Public JSON schema for metadata-only validation; it does not grant runtime authority.
SchemaChat Control PlanPublic JSON schema for metadata-only validation; it does not grant runtime authority.
SchemaChat Control RecipePublic JSON schema for metadata-only validation; it does not grant runtime authority.
SchemaChatbox Action PlanPublic JSON schema for metadata-only validation; it does not grant runtime authority.
SchemaChatbox Action Queue PlanPublic JSON schema for metadata-only validation; it does not grant runtime authority.
SchemaConsent Action PlanPublic JSON schema for metadata-only validation; it does not grant runtime authority.
SchemaDiagnostic ManifestPublic JSON schema for metadata-only validation; it does not grant runtime authority.
SchemaEndpoint ManifestPublic JSON schema for metadata-only validation; it does not grant runtime authority.
SchemaEndpoint Plugin InstallPublic JSON schema for metadata-only validation; it does not grant runtime authority.
SchemaEndpoint Plugin SubmissionPublic JSON schema for metadata-only validation; it does not grant runtime authority.
SchemaEvidence PacketPublic JSON schema for metadata-only validation; it does not grant runtime authority.
SchemaLlms ProfilePublic JSON schema for metadata-only validation; it does not grant runtime authority.
SchemaLocal Control Action PlanPublic JSON schema for metadata-only validation; it does not grant runtime authority.
SchemaLocal Control EvidencePublic JSON schema for metadata-only validation; it does not grant runtime authority.
GatewayGateway evidence schemaCustom gateway claims export as reviewable evidence.
QualityQuality evidence schemaPre-release quality gates stay artifact-backed.
DeployDeployment packet schemaVerification without deployment authority.
SearchSearch packet schemaDiscovery metadata that does not imply execution.
Shape can be checked locally
Use the browser validator to inspect manifest fields and export receipts without uploading endpoint data.
Open validatorEvidence has a schema
Evidence packets, quality records, and deployment checks are structured so claims can be compared instead of guessed.
Evidence docsSchemas do not activate endpoints
A valid JSON document proves shape, not safety certification, credentials, runtime approval, or autonomous execution.
Technical boundaryOperating boundary
Public clarity, local authority.
Public product, docs, download, and validation pages do not dispatch desktop commands, probe localhost, upload files, collect runtime telemetry, or claim runtime safety certification. Account credentials are accepted only on dedicated account routes.