{
"id": "io.github.example.notes-app",
"version": "1.0.0",
"name": "Notes App",
"service": { "entry": "service/service.ts" },
"contracts": ["contracts/github.ts"],
"uses": { "github@1": "io.github.iro-labs.github" },
"requires": {
"notes@1": { "capabilities": ["notes.read", "notes.write"], "reason": "Save your notes." }
},
"optionalRequires": {
"llm@1": { "capabilities": ["llm.chat"], "reason": "Optional summaries." }
},
"network": ["https://api.example.com"],
"ui": {
"entry": "ui/index.html",
"layouts": ["full", "compact"],
"launchTargets": ["embedded", "window", "desktop"]
},
"jobs": [
{ "id": "morning", "entry": "jobs/morning.ts", "schedule": "0 8 * * *", "catchUp": "once" }
]
}
- One app role:
service, contracts, uses. No connectors.
requires is asked at install; optionalRequires can be asked later at runtime through the trusted sheet. Sensitive capabilities can require a one-use confirmation per call.
network is declared origins (exact https), enforced by the per-app kernel proxy before DNS. Service origins are declared, not granted — the service needs them to work.
ui.layouts default ["full"]; launchTargets default ["embedded", "window"]. desktop needs no extra code.
jobs entries are cron lines in local time with once (default) or skip catch-up. Job code runs as the app in a fresh sandbox per run.