Joltspecifications

Jolt project specifications

Requests
for Comments

Normative, implementable documents for the protocol surface: terminology, encodings, sender and receiver behaviour, compatibility, errors, and security. These are project RFCs, not IETF publications.

0001

Experimental Draft · Implemented with known gaps

Signed Path Records and Resolution

The complete specification for identity addresses, CID construction, canonical signed records, validation, state replay, candidate selection, end-to-end publication and resolution, architectural boundaries, security, and conformance.

0002

Experimental Draft · Implemented v1

Device Authorization and Revocation

The root-signed authority chain, exact canonical bytes, device signing and encryption keys, revocation cutoffs, validation failures, and legacy-root migration.

0003

Experimental Draft · Implemented v1

Per-Device Writer Logs and Deterministic Merge

Independent device hash chains, singleton and append path operations, authority filtering, deterministic conflict resolution, enumeration, and network synchronization.

0004

Experimental Draft · Envelope and daemon operations implemented; device-key custody experimental

Encrypted Objects and Private Device Access

The HPKE and ChaCha20-Poly1305 envelope, canonical signatures and authenticated data, device recipient selection, encrypted indexes, access states, rewrap, and honest revocation limits.

0005

Experimental Draft · Design only

Community Identities and Membership

Communities as normal Jolt identities, watch versus join, join policies, grants, invites, revocations, member-only state, verification rules, and the decisions still open before implementation.

0006

Experimental Draft · Design only

Community-Scoped App Indexes and Local Discovery

Member-signed submissions, community curation, public and encrypted indexes, local search, lazy CID fetch, removal semantics, and why relays never own ranking or inclusion.

0007

Experimental Draft · Implemented v0

Capability-Scoped Local App Sessions

The Console/app trust boundary, session lifecycle, bearer-token handling, complete capability grammar, strict identity and path scoping, HTTP operations, revocation, and current device-binding gaps.