Jolt project specifications
Requests
for Comments
Normative, implementable documents for the protocol surface: terminology, encodings, sender and receiver behaviour, compatibility, errors, and security. These are project RFCs, not IETF publications.
Experimental Draft · Implemented with known gaps
Signed Path Records and Resolution
The complete specification for identity addresses, CID construction, canonical signed records, validation, state replay, candidate selection, end-to-end publication and resolution, architectural boundaries, security, and conformance.
Experimental Draft · Implemented v1
Device Authorization and Revocation
The root-signed authority chain, exact canonical bytes, device signing and encryption keys, revocation cutoffs, validation failures, and legacy-root migration.
Experimental Draft · Implemented v1
Per-Device Writer Logs and Deterministic Merge
Independent device hash chains, singleton and append path operations, authority filtering, deterministic conflict resolution, enumeration, and network synchronization.
Experimental Draft · Envelope and daemon operations implemented; device-key custody experimental
Encrypted Objects and Private Device Access
The HPKE and ChaCha20-Poly1305 envelope, canonical signatures and authenticated data, device recipient selection, encrypted indexes, access states, rewrap, and honest revocation limits.
Experimental Draft · Design only
Community Identities and Membership
Communities as normal Jolt identities, watch versus join, join policies, grants, invites, revocations, member-only state, verification rules, and the decisions still open before implementation.
Experimental Draft · Design only
Community-Scoped App Indexes and Local Discovery
Member-signed submissions, community curation, public and encrypted indexes, local search, lazy CID fetch, removal semantics, and why relays never own ranking or inclusion.
Experimental Draft · Implemented v0
Capability-Scoped Local App Sessions
The Console/app trust boundary, session lifecycle, bearer-token handling, complete capability grammar, strict identity and path scoping, HTTP operations, revocation, and current device-binding gaps.