Interactive scientific paper
A paper whose figures are live: readers change a parameter and the model in the paper recomputes, from the code and data that ship with it.
IDOP 1.0 · open file format · application/vnd.idop+zip
IDOP is an open file format in which a document carries its own interface, logic and data. IDOP LABS builds the format and the tools to create, open, run and share it — so a report can recompute, a lesson can remember, and a tool can travel as a single file.
Opened in a reader, it works: change the inputs and the document recomputes. What you enter is saved back into the file.
§ 01The problem
A report, a price list, a lesson or a study arrives as a document: portable, durable, yours to keep — and inert. The calculations happened somewhere else, and the numbers on the page cannot be questioned or changed.
The interactive version usually lives in an application instead: on a platform, behind an account, in a format only that service can open. It works until the subscription, the export or the service ends.
IDOP explores what happens when the two are one thing — a file that keeps the portability of a document and gains the behaviour of an application, without giving up the safety people expect from opening a document.
§ 02Introducing IDOP
An .idop file is a ZIP archive with a fixed structure. Each part has one job, and only one part can run.
code/
code/
storage/
idop.json
budget.idop
mimetypeIdentificationThe first entry of every package, stored uncompressed. Its content puts the media type at byte offset 38, so software can recognise an IDOP file without unpacking it.
application/vnd.idop+zipidop.jsonManifestWhat the document is and what it may ask for: the application, the document’s identity and revision lineage, the entry point, and every network capability with the origins, methods and purpose it declares. It never contains a secret.
{
"format": "https://idoplabs.com/ns/idop/package",
"formatVersion": "1.0",
"entryPoint": "code/index.html",
"application": { "id": "com.example.budget",
"title": "Project budget" },
"requiredCapabilities": []
}code/Interface and logicHTML, CSS, JavaScript and JSON — the only part of a package that can run. It runs inside the reader’s sandbox, with no network and no access to the reader. Inline scripts, remote URLs and dynamic evaluation are refused before anything runs.
code/
├── index.html <script type="module" src="app.js">
├── app.js await idop.storage.write(…)
└── style.cssresources/Passive filesImages, fonts and data files the interface displays. The reader serves them to the document by path; nothing under resources/ is ever executed, and a script placed there causes the package to be refused.
resources/
├── icon.svg
├── fonts/inter.woff2
└── data/rates.csvstorage/Saved stateThe document’s data, saved in the file. The document reads and writes it only through the Runtime API; changes stay in a working copy until the user saves, and every Save produces a new revision.
// inside the document
const { text } = await idop.storage.read('model.json');
await idop.storage.write('model.json', next);_idop/Reserved by the specificationNames the specification keeps for itself. IDOP 1.1 defines an optional thumbnail here; publisher signatures and encryption metadata are reserved for future versions. A 1.0 reader ignores this root.
_idop/
├── thumbnail.png 1.1 draft
├── signatures/ reserved
└── encryption/ reservedextensions/Extension dataData for named extensions, each under its own reverse-domain namespace, so extensions cannot collide with each other or with the format.
extensions/
└── com.example.review/
└── comments.json§ 03How it works
A reader treats every .idop file as untrusted. It validates the whole package before running a line of it, runs the code in an isolated sandbox, and answers each request the document makes — or refuses it.
Input
.idop file
Untrusted until proven otherwise.
Step 1 · Reader
Validation before execution
Any failure refuses the whole file, with a stable error code. Nothing runs before all checks pass.
Step 2 · Running
Sandbox
The document’s code. Opaque origin, no network, no access to the reader or other documents.
code/**Reader
Answers each request — or refuses it.
storage/Step 3 · Save
A new revision
Only storage/ and the revision in idop.json change. The result is validated again before it replaces the file.
§ 04What can be built
Some of these exist today as templates you can open. Others are demonstrations of what the format allows; they are labelled as such.
A paper whose figures are live: readers change a parameter and the model in the paper recomputes, from the code and data that ship with it.
Budgets, loans and repayment plans whose formulas cannot drift from the numbers, because both are in the same file.
A dashboard that carries a snapshot of its data, so it can be emailed, archived and reopened years later — or, with permission, refreshed from a declared source.
Lessons, exercises and quizzes in one file a student keeps: progress is saved inside it, and it works offline.
Boards, timelines and decision records that belong to the project, not to a subscription.
A small simulation — a beam under load, a circuit, a heat exchanger — that a colleague can open and operate without installing the tool it was built in.

§ 05IDOP Cloud
IDOP Cloud is the web environment for the format. It is available today, in any modern browser.
Available
§ 06Developers
If you can write a web page, you can write an IDOP document. The specification defines the package, a small Runtime API, and what a reader must check — so a document behaves the same in every conforming reader.
app.js
const button = document.querySelector('#add');
let count = 0;
try {
count = JSON.parse((await idop.storage.read('count.json')).text).count;
} catch (error) {
if (error.code !== 'IDOP-STORAGE-NOT-FOUND') throw error;
}
button.textContent = String(count);
button.addEventListener('click', async () => {
count += 1;
button.textContent = String(count);
await idop.storage.write('count.json', JSON.stringify({ count }));
});index.html
<!doctype html>
<html lang="en">
<head>
<meta charset="utf-8">
<title>Counter</title>
<script type="module" src="app.js"></script>
</head>
<body><button id="add">0</button></body>
</html>idop.json
{
"format": "https://idoplabs.com/ns/idop/package",
"formatVersion": "1.0",
"runtimeApiVersion": "1.0",
"entryPoint": "code/index.html",
"application": { "id": "com.example.counter", "version": "1.0.0", "title": "Counter" },
"document": {
"id": "4df56319-e383-4ae8-a519-faa7f4866f90",
"revisionId": "2e43a209-0a66-4f54-b545-dae25d3b89d0",
"parentRevisionId": null,
"createdAt": "2026-10-01T00:00:00Z",
"modifiedAt": "2026-10-01T00:00:00Z"
},
"state": { "schemaVersion": "1.0.0" },
"requiredFeatures": ["idop.core-storage-v1"],
"optionalFeatures": [],
"requiredCapabilities": [],
"optionalCapabilities": [],
"environmentBindings": [],
"credentialBindings": [],
"extensions": {}
}Command line
# Would a reader accept it?
idop validate counter/
# What would it ask for?
idop inspect counter.idop
# Pack a directory into a deterministic package
idop pack counter/ --output counter.idopThe complete counter document from Annex C of the specification. Read the walkthrough.
§ 07Security model
Opening a file should not be an act of faith. These are the rules every IDOP reader follows — the specification states each one as a requirement.
Static checks are defence in depth; the sandbox is the boundary. No software is free of defects — if you find one, tell us.
§ 08An open format
A file format is only as durable as its description. IDOP is specified in public so that anyone can write a reader, a producer or a validator — and so that documents written today stay readable.
application/vnd.idop+zip, identifiable from the first bytes of the file. Registration with IANA is in preparation.
§ 09Research and vision
We think the most useful documents of the next decades will not only describe a calculation, a model or a procedure — they will contain it, run it safely for whoever opens them, and remain theirs to keep.
What we study
IDOP Cloud runs in the browser. Start from a template, open a file you were sent, or keep your own — no installation, and no account needed just to open a document.