Apps, services and contracts
One role: an app may provide capabilities through its service, use capabilities, and have a UI and jobs. Connectors are services now.
- Manifest (
iro.json):service,contracts,uses. Noconnectorsanymore. - Services run in a hardened Deno subprocess inside the OS sandbox.
ctx.httpis performed by the kernel; API keys are typed into Iro’s page only and sent solely to the manifest’sapiOrigins. - App contracts (e.g.
github@1) are checked JSON Schema files. Inputs with undeclared fields are refused, outputs stripped. A consumer names whose contract it means inuses("github@1": "<package id>"); grants live under the fullpackage/contract:capabilityname so two packages’githubnever mix. Own contracts are granted at install. - Resolution:
uses[ref], else the caller’s own package. Unknown or unbound providers areMethodNotFound/NotBound— never silent. - Accounts live on the app’s page.
accounts.connectasks in Iro’s prompt window for the caller’s own service and returns only{ id, label }. Jobs can’t call it. - Storage: each app has its own
storage@1kv namespace without a grant, pushed live to every open document. Uninstall clears it. - Jobs (
defineJob) run on a cron schedule as their app, one fresh Deno process per run, catch-up once or skip after sleep.