packages/contracts — protocol notes·
@tiny-vercel/contracts is types + string constants only. It is the ABI that the
web app, the Cloudflare worker, the iOS app, the CLI daemon (apps/cli, npx tiny-vercel), Sticky and
endpoint devices all agree on. Any change is a protocol change: add a row here.
| Module | Covers | Source of truth (tinyai-id) |
|---|---|---|
sse.ts |
chat SSE frame vocabulary, seq, [DONE], 15 s keepalive |
lib/chat/events.ts, app/api/chat/route.ts pump loop |
chat.ts |
POST /api/chat body + every x-tiny-* header |
app/api/chat/route.ts |
auth.ts |
tiny_session cookie, JWT TTLs, SessionUser |
lib/auth.ts |
devices.ts |
enroll/heartbeat/event/ask bodies, relay bodies, envelopes, relay_messages row, exact worker error strings, RelaySendResult |
app/api/devices/*, worker devices.ts relay.ts relay-shared.ts, lib/chat/relay-send.ts |
push.ts |
PushPayload limits, send result |
worker push.ts |
Still to lift (R6–R8): notification/event ring shapes (events.ts, ring.ts), job/schedule bodies (scheduler.ts), x402 Accept/Challenge/QuoteFields and wallet responses (lib/x402/*), endpoint-device call envelope (devices.ts DeviceEndpointCallRoute), transcript/media shapes. The endpoint-device HTTP contract (what a device must serve) is documented and exercised in examples/echo-device/README.md.
Changelog·
- 0.0.0 (R2) — initial extraction, types verified against source by reading; not yet enforced by tests.
- 0.0.0 (R3) —
auth.tsverified against the portedlib/auth.ts: SessionUser is{sub, login, name?, avatar?}(no email claim in the JWT; email lives only in D1). CLI code/token audiences:tiny-cli-code(5 min),tiny-cli(90 d). iOS deep-link schemetinyapp://authis an allowlisted constant in/api/auth/cli— a client ABI, kept.