Start

Core concepts

Documents, readers, sessions, revisions and capabilities — the vocabulary of IDOP.

Document

An IDOP document is a single .idop file: a ZIP archive with a fixed structure containing a manifest, code, passive resources and saved state. It is identified by document.id in its manifest, which never changes, and by a revisionId, which changes on every save.

Reader

A reader is software that opens IDOP documents. A conforming reader validates the whole file before running anything, runs the document’s code in an isolated sandbox, answers the document’s requests within declared and granted limits, and writes state only when the user saves. IDOP Cloud includes a reader.

Producer

A producer is anything that writes IDOP packages: the idop pack tool, IDOP Cloud when it saves, or an AI assistant through the connector. Producers should write packages deterministically.

Session

Opening a document creates a session: one isolated execution context with its own channel to the reader. Sessions cannot see each other.

Working copy and revisions

On open, the reader copies storage/ into a working copy. The document reads and writes the working copy; the file is untouched until the user saves. Each save produces a new revision: parentRevisionId becomes the previous revisionId, and a new revisionId is assigned.

Capability

A capability is a declared permission to make network requests: exact HTTPS origins, allowed methods, an optional credential binding, and a purpose shown to the user. Without one, a document has no network access.

Credential binding

A credential binding names a credential the document needs, without naming a service or containing a secret. The reader holds the actual credential, pinned by the user to specific origins, and attaches it to requests on its side.

Self-declared metadata

The manifest’s application values — title, version, icon — are self-declared. A reader shows them, but they are not verified. In IDOP 1.0 there is no publisher signature.