IDOP 1.0 · open file format · application/vnd.idop+zip

Interactive documents, as files.

IDOP is an open file format in which a document carries its own interface, logic and data. IDOP LABS builds the format and the tools to create, open, run and share it — so a report can recompute, a lesson can remember, and a tool can travel as a single file.

  • Validated in full before anything runs
  • Sandboxed, with no network unless you allow it
  • Your data saved inside the file

budget.idop

Project budget

Total€264,000

Saved in the file · storage/model.jsonSandboxed · no network

Opened in a reader, it works: change the inputs and the document recomputes. What you enter is saved back into the file.

§ 01The problem

Documents hold information. Applications do the work.

A report, a price list, a lesson or a study arrives as a document: portable, durable, yours to keep — and inert. The calculations happened somewhere else, and the numbers on the page cannot be questioned or changed.

The interactive version usually lives in an application instead: on a platform, behind an account, in a format only that service can open. It works until the subscription, the export or the service ends.

IDOP explores what happens when the two are one thing — a file that keeps the portability of a document and gains the behaviour of an application, without giving up the safety people expect from opening a document.

Portability and interactivityStatic documents are portable but not interactive. Web applications are interactive but tied to a service. Spreadsheets sit between. IDOP aims for the upper right: interactive and portable.Portability — travels as a file, works offline, outlives the serviceInteractivity — computes, responds, remembersStatic documentsportable, but inertWeb applicationsinteractive, but tied to a serviceSpreadsheetsformulas, not interfacesIDOPinteractive and portable
An illustration of the idea, not a measurement.

§ 02Introducing IDOP

One file. Content, interface, logic and data — and the rules it runs by.

An .idop file is a ZIP archive with a fixed structure. Each part has one job, and only one part can run.

code/

Interface

HTML and CSS: what the reader sees and touches. The same web technology people already know how to write.

code/

Logic

JavaScript that computes, validates and responds — running in a sandbox, never with the reader’s privileges.

storage/

Data

What the user enters, saved back into the file as a new revision. Close it, send it, open it a year later.

idop.json

Manifest

What the document is, and exactly what it may ask for: which servers, which methods, for what purpose.

budget.idop

mimetypeIdentification

Spec §4.2

The first entry of every package, stored uncompressed. Its content puts the media type at byte offset 38, so software can recognise an IDOP file without unpacking it.

Executable
No
Written by
Producer
application/vnd.idop+zip

idop.jsonManifest

Spec §7

What the document is and what it may ask for: the application, the document’s identity and revision lineage, the entry point, and every network capability with the origins, methods and purpose it declares. It never contains a secret.

Executable
No
Written by
Producer; the reader updates the revision on Save
{
  "format": "https://idoplabs.com/ns/idop/package",
  "formatVersion": "1.0",
  "entryPoint": "code/index.html",
  "application": { "id": "com.example.budget",
                   "title": "Project budget" },
  "requiredCapabilities": []
}

code/Interface and logic

Spec §8

HTML, CSS, JavaScript and JSON — the only part of a package that can run. It runs inside the reader’s sandbox, with no network and no access to the reader. Inline scripts, remote URLs and dynamic evaluation are refused before anything runs.

Executable
Yes — in the sandbox only
Written by
Producer
code/
├── index.html   <script type="module" src="app.js">
├── app.js       await idop.storage.write(…)
└── style.css

resources/Passive files

Spec §4.3

Images, fonts and data files the interface displays. The reader serves them to the document by path; nothing under resources/ is ever executed, and a script placed there causes the package to be refused.

Executable
No
Written by
Producer
resources/
├── icon.svg
├── fonts/inter.woff2
└── data/rates.csv

storage/Saved state

Spec §10

The document’s data, saved in the file. The document reads and writes it only through the Runtime API; changes stay in a working copy until the user saves, and every Save produces a new revision.

Executable
No
Written by
The reader, on Save
// inside the document
const { text } = await idop.storage.read('model.json');
await idop.storage.write('model.json', next);

_idop/Reserved by the specification

Spec §4.3

Names the specification keeps for itself. IDOP 1.1 defines an optional thumbnail here; publisher signatures and encryption metadata are reserved for future versions. A 1.0 reader ignores this root.

Executable
No
Written by
Defined by later versions
_idop/
├── thumbnail.png    1.1 draft
├── signatures/      reserved
└── encryption/      reserved

extensions/Extension data

Spec §4.3

Data for named extensions, each under its own reverse-domain namespace, so extensions cannot collide with each other or with the format.

Executable
No
Written by
Producers of an extension
extensions/
└── com.example.review/
    └── comments.json

§ 03How it works

The file asks. The reader decides. You are asked before anything leaves your device.

A reader treats every .idop file as untrusted. It validates the whole package before running a line of it, runs the code in an isolated sandbox, and answers each request the document makes — or refuses it.

Input

.idop file

Untrusted until proven otherwise.

Step 1 · Reader

Validation before execution

  1. Size limits
  2. ZIP structure, parsed independently
  3. mimetype
  4. Every path
  5. Bounded decompression, CRC
  6. Manifest
  7. Executable boundary
  8. Capabilities and consent

Any failure refuses the whole file, with a stable error code. Nothing runs before all checks pass.

Step 2 · Running

Sandbox

The document’s code. Opaque origin, no network, no access to the reader or other documents.

code/**

Reader

Answers each request — or refuses it.

  • Storage — a working copy of storage/
  • Network — only declared origins, after consent
  • Credentials — injected by the reader, never shown to code

Step 3 · Save

A new revision

Only storage/ and the revision in idop.json change. The result is validated again before it replaces the file.

The processing model of an IDOP reader, simplified. The normative text is in the specification, sections 9 to 12.

§ 04What can be built

Anything that is better used than read.

Some of these exist today as templates you can open. Others are demonstrations of what the format allows; they are labelled as such.

diffusion-study.idop

ResearchDemonstration

Interactive scientific paper

A paper whose figures are live: readers change a parameter and the model in the paper recomputes, from the code and data that ship with it.

loan-calculator.idop

FinanceTemplate available

Financial model

Budgets, loans and repayment plans whose formulas cannot drift from the numbers, because both are in the same file.

q3-operations.idop

DataDemonstration

Analytics dashboard

A dashboard that carries a snapshot of its data, so it can be emailed, archived and reopened years later — or, with permission, refreshed from a declared source.

fractions-unit-3.idop

EducationTemplate available

Interactive course

Lessons, exercises and quizzes in one file a student keeps: progress is saved inside it, and it works offline.

launch-board.idop

TeamsTemplate available

Project workspace

Boards, timelines and decision records that belong to the project, not to a subscription.

beam-deflection.idop

EngineeringDemonstration

Engineering simulation

A small simulation — a beam under load, a circuit, a heat exchanger — that a colleague can open and operate without installing the tool it was built in.

IDOP Cloud with the Net Worth template open: summary figures, a twelve-month chart, and lists of assets and debts.

§ 05IDOP Cloud

The place to open, run, keep and share IDOP documents.

IDOP Cloud is the web environment for the format. It is available today, in any modern browser.

Available

  • Open any .idop file — no account needed just to open one
  • Start from forty first-party templates
  • Keep documents and files in your cloud, in folders
  • Share by link, with an expiry and an optional password
  • Install it as an app; it opens .idop files from your system

§ 06Developers

A web app in a ZIP, with a contract.

If you can write a web page, you can write an IDOP document. The specification defines the package, a small Runtime API, and what a reader must check — so a document behaves the same in every conforming reader.

app.js

code/app.js
const button = document.querySelector('#add');
let count = 0;
try {
  count = JSON.parse((await idop.storage.read('count.json')).text).count;
} catch (error) {
  if (error.code !== 'IDOP-STORAGE-NOT-FOUND') throw error;
}
button.textContent = String(count);
button.addEventListener('click', async () => {
  count += 1;
  button.textContent = String(count);
  await idop.storage.write('count.json', JSON.stringify({ count }));
});

index.html

code/index.html
<!doctype html>
<html lang="en">
  <head>
    <meta charset="utf-8">
    <title>Counter</title>
    <script type="module" src="app.js"></script>
  </head>
  <body><button id="add">0</button></body>
</html>

idop.json

idop.json
{
  "format": "https://idoplabs.com/ns/idop/package",
  "formatVersion": "1.0",
  "runtimeApiVersion": "1.0",
  "entryPoint": "code/index.html",
  "application": { "id": "com.example.counter", "version": "1.0.0", "title": "Counter" },
  "document": {
    "id": "4df56319-e383-4ae8-a519-faa7f4866f90",
    "revisionId": "2e43a209-0a66-4f54-b545-dae25d3b89d0",
    "parentRevisionId": null,
    "createdAt": "2026-10-01T00:00:00Z",
    "modifiedAt": "2026-10-01T00:00:00Z"
  },
  "state": { "schemaVersion": "1.0.0" },
  "requiredFeatures": ["idop.core-storage-v1"],
  "optionalFeatures": [],
  "requiredCapabilities": [],
  "optionalCapabilities": [],
  "environmentBindings": [],
  "credentialBindings": [],
  "extensions": {}
}

Command line

terminal
# Would a reader accept it?
idop validate counter/

# What would it ask for?
idop inspect counter.idop

# Pack a directory into a deterministic package
idop pack counter/ --output counter.idop

The complete counter document from Annex C of the specification. Read the walkthrough.

§ 07Security model

A document is untrusted code. The design starts there.

Opening a file should not be an act of faith. These are the rules every IDOP reader follows — the specification states each one as a requirement.

Validation before execution

The whole package is parsed and checked — structure, paths, sizes, manifest, executable boundary — before any of it runs. One failure refuses the file.

An isolated sandbox

Document code runs in an opaque origin, with no access to the reader, to other documents, or to the browser’s storage and cookies.

No network by default

A document can reach only the exact origins its manifest declares, with the methods it lists — and only after you allow it.

Secrets stay with the reader

API keys are held by the reader and added to requests on its side. A document never sees a key, and a file never contains one.

Least privilege, stated in advance

Every capability carries a purpose shown to you. A change to the code or to what it asks for invalidates an earlier approval.

Explicit saves, kept revisions

Nothing is written into the file until you save. Each save is a new revision, validated again before it replaces the old file.

Static checks are defence in depth; the sandbox is the boundary. No software is free of defects — if you find one, tell us.

§ 09Research and vision

What a document could become.

We think the most useful documents of the next decades will not only describe a calculation, a model or a procedure — they will contain it, run it safely for whoever opens them, and remain theirs to keep.

What we study

  • Secure execution of untrusted documents
  • Data portability and durable formats
  • Computational and explorable documents
  • Consent and capability models
  • Documents written by and with AI
Research at IDOP LABS

Start with a document. Keep the file.

IDOP Cloud runs in the browser. Start from a template, open a file you were sent, or keep your own — no installation, and no account needed just to open a document.