Apps, services and contracts

One role: an app may provide capabilities through its service, use capabilities, and have a UI and jobs. Connectors are services now.

  • Manifest (iro.json): service, contracts, uses. No connectors anymore.
  • Services run in a hardened Deno subprocess inside the OS sandbox. ctx.http is performed by the kernel; API keys are typed into Iro’s page only and sent solely to the manifest’s apiOrigins.
  • App contracts (e.g. github@1) are checked JSON Schema files. Inputs with undeclared fields are refused, outputs stripped. A consumer names whose contract it means in uses ("github@1": "<package id>"); grants live under the full package/contract:capability name so two packages’ github never mix. Own contracts are granted at install.
  • Resolution: uses[ref], else the caller’s own package. Unknown or unbound providers are MethodNotFound / NotBound — never silent.
  • Accounts live on the app’s page. accounts.connect asks in Iro’s prompt window for the caller’s own service and returns only { id, label }. Jobs can’t call it.
  • Storage: each app has its own storage@1 kv namespace without a grant, pushed live to every open document. Uninstall clears it.
  • Jobs (defineJob) run on a cron schedule as their app, one fresh Deno process per run, catch-up once or skip after sleep.

See manifest and contracts for the exact shapes.