Contracts
Generated from the contract sources. Until the generator script lands, this page is hand-kept in sync with packages/contracts/src and iro-apps/*/contracts — drift is a bug.
Core contracts (kernel)
| Contract | Capabilities | Notes |
|---|---|---|
calendar@1 |
calendars.read, events.read |
Read-only in v1. Repeating events expanded; all-day = days (end exclusive), timed = moments with offset. Merges accounts. |
notes@1 |
notes.read, notes.write |
No delete in v1. Note id is the path inside the picked folder. Picks one account. |
tasks@1 |
tasks.read |
GitHub issues shaped provider-neutral. Merges accounts. |
notify@1 |
notify.send |
Not sensitive, no link. Provided by Iro itself. |
storage@1 |
kv per app, no grant | get/set/delete/list + storage@1.changed pushes to every open document. Limits: 64 KiB values, 1000 keys, 4 MiB per app. |
accounts@1 |
accounts.connect |
Trusted prompt window, caller’s own service only, returns { id, label }. Jobs can’t call it. |
llm@1 (1.2) |
llm.chat, llm.embed, llm.choose, llm.models |
Routed by tier/fallback/budget; tool calls in 1.2; model: handle is opaque per app. Streams via onChunk, stoppable via signal. |
tools@1 |
tools.use |
Answered by Iro alone. list what the app declares + granted + provided; call runs one tool as the app. Sensitive always asks. |
iro.install@1 |
iro.install.request |
Stores only. { url, sha256, catalog? } → installed/cancelled. |
iro.packages@1 |
iro.packages.read |
Installed ids + versions only. |
App contracts
Declared in contracts/*.ts with defineAppContract, built to checked JSON by iro build:
github@1(GitHub app):repos.read(listRepos),actions.read(listRuns,getRun), sensitiveactions.run(rerunRun,rerunFailedJobs). Repo ids checked against GitHub naming rules before URLs; run ids are integers.
Consumers declare "github@1": "<package id>" in uses and call through dynamic client namespaces; the kernel resolves from the caller’s own manifest, never params.