Standards
Introducing IDOP 1.0
The first stable version of the IDOP file format — what it is, what is frozen, and what comes next.
Today we are publishing the IDOP Format Specification 1.0 as a Candidate Recommendation. IDOP is a file format for interactive documents: one .idop file carries a document’s interface, its logic, its passive resources and its saved state, and any conforming reader can open it, check it and run it safely.
What 1.0 fixes
A Candidate Recommendation means the parts other software depends on are frozen:
- The container. A ZIP archive with a strict profile. Its first entry,
mimetype, is stored uncompressed and containsapplication/vnd.idop+zip, which puts the media type at a fixed offset in every package. - The manifest.
idop.json, validated against a published JSON Schema, identifies the format with an HTTPS URI under idoplabs.com — not a trade name — and declares the application, the document’s revision lineage and every capability it may request. - The executable boundary. Only
code/may contain HTML, JavaScript and CSS, with no inline scripts, remote URLs or dynamic evaluation. - The Runtime API. A frozen
globalThis.idopwith storage, permissioned network requests, configuration, save and viewer methods — and stable error codes.
From here on, changes to the 1.0 text are editorial. New features arrive in minor versions, which may only add: a valid 1.0 document stays valid.
What a reader must do
The specification is as much about readers as about files. A conforming reader validates the whole package before exposing any of it to code, runs the code in an isolated context with no network, answers requests only within what the manifest declares and the user grants, holds credentials itself, and writes state only when the user saves — as a new revision.
What we have built on it
IDOP Cloud, at cloud.idoplabs.com, is our reader: it opens any .idop file without an account, stores documents for signed-in users, and shares them by link. It runs the same Rust core, compiled to WebAssembly, as our command-line validator.
What comes next
- IDOP 1.1, in working draft, adds one optional feature: a preview image for file managers and link previews. Read the draft.
- Registration of the media types with IANA is in preparation.
- Publisher signatures are reserved in the format and under research.
The specification is published under CC BY 4.0. If you build a reader, a producer or a validator, we would like to hear about it: spec@idoplabs.com.