Manifest (iro.json)

{
    "id": "io.github.example.notes-app",
    "version": "1.0.0",
    "name": "Notes App",
    "service": { "entry": "service/service.ts" },
    "contracts": ["contracts/github.ts"],
    "uses": { "github@1": "io.github.iro-labs.github" },
    "requires": {
        "notes@1": { "capabilities": ["notes.read", "notes.write"], "reason": "Save your notes." }
    },
    "optionalRequires": {
        "llm@1": { "capabilities": ["llm.chat"], "reason": "Optional summaries." }
    },
    "network": ["https://api.example.com"],
    "ui": {
        "entry": "ui/index.html",
        "layouts": ["full", "compact"],
        "launchTargets": ["embedded", "window", "desktop"]
    },
    "jobs": [
        { "id": "morning", "entry": "jobs/morning.ts", "schedule": "0 8 * * *", "catchUp": "once" }
    ]
}
  • One app role: service, contracts, uses. No connectors.
  • requires is asked at install; optionalRequires can be asked later at runtime through the trusted sheet. Sensitive capabilities can require a one-use confirmation per call.
  • network is declared origins (exact https), enforced by the per-app kernel proxy before DNS. Service origins are declared, not granted — the service needs them to work.
  • ui.layouts default ["full"]; launchTargets default ["embedded", "window"]. desktop needs no extra code.
  • jobs entries are cron lines in local time with once (default) or skip catch-up. Job code runs as the app in a fresh sandbox per run.