Compositional template language

The closed Template/Expression language is the common execution substrate for compiled applications, integrations and domain definitions—not a provider handler registry.

Model

A Template is serializable behavior. Primitive and composed templates can be substituted at the same boundary. A Process is one execution of an immutable definition, with explicit continuation, memory, outcome and effect occurrences. Sequential composition, choice, failure, recovery, iteration and named scopes are inspectable nodes. Derived fanout/product builders are sequential; parallel fibers and joins remain future work.

Expressions contain JSON values, lexical binders, arrays/records, traversal, folds, bounded recursion and finite scalar operations. No Custom node, arbitrary runtime callback, dynamic module import or source evaluator exists. Application source is parsed and lowered at authoring time. Trusted macros may construct closed syntax, but cannot extend runtime execution authority.

The SDK exposes branded immutable input/error/output-indexed arrows. Wire admission still validates the complete syntax: TypeScript types are not a substitute for validation. Do not export a function named then from a dynamically imported SDK module; the AST tag is then, but its builder is compose, avoiding module-namespace thenable behavior.

Checked semantic failures can become data through closed attempt expressions. Malformed syntax, illegal scope and resource exhaustion are not ordinary catchable validation errors. Introspectability does not imply termination: fuel, depth and encoded-size bounds are host policy.

Execution and interaction

The pure sequential reducer yields generic effects rather than performing IO. HTTP, clock, host timestamp parsing, human/timed waits, protected signing/derivation, scoped records and child creation have fixed schemas. Process-local memory operations are explicit; authorized edits may change that memory while waiting without replaying prior external effects.

The application service enforces process/field access, interaction contracts, lifecycle commands, audit and optimistic concurrency. A registration separates immutable execution authority from versioned presentation. Reads can overlay current presentation while retaining the process's pinned execution and original process mode. The continuation stores structural paths, not closures or copied executable tails.

Effect persistence and authority

Each occurrence has an identity distinct from a retrying worker. A compare-and-set claim precedes dispatch; a durable outcome precedes continuation. Concurrent workers cannot claim the same occurrence. A thrown transport exception or uncertain outcome commit does not prove the remote operation failed: the process is held, not blindly redelivered.

Protected values remain encrypted handles rather than ordinary context/history strings. Exact execution approvals bind startup state/policy and static derivations as well as the program. The main deployment preserves trusted template-author authority over configured capabilities; the standalone host requires explicit policy. Neither presentation metadata nor a claimed id grants authority. Destination, method, path and secret-placement policies constrain HTTP use. Redirects are not followed; request/response size and time are bounded. Providers must still be trusted not to encode and reflect secrets—literal echo detection is defense in depth, not noninterference.

See deployment capabilities and migration for endpoint bindings, keyrings, activation and offline import. No live reconciliation UI or exactly-once external execution guarantee follows from local CAS. File locks left by a crash are not automatically stolen; recovery requires operator evidence.

Libraries, not magic

Dune, Slack, Telegram, Notion, Gemini, Sheets and Safe are inspectable integration definitions. OAuth/signing use generic protected operations; provider endpoints and request/response rules remain outside Platform. Domain ABI/RLP, Safe batches, Solana messages/PDA search, amounts and calendar logic are inspectable compositions of generic byte/crypto/integer/data primitives.

All repository application definitions compile to the same runtime syntax. Frozen compatibility fixtures and independent encoders compare full outputs, including payload bytes. This does not census definitions edited outside the repository; unknown historical source is rejected during migration rather than admitted as arbitrary JavaScript.

Verification

Run package applications/main/tests/typechecks, npm run check:packed:language, dependency gates and the complete application verification. Tests cover wire rejection, scope/hygiene, composition, serialization/restart, distinct effects, fault windows, CAS races, protected authority, provider fixtures, interaction/audit and migration. Real identity, provider and production-storage configuration remain separately authorized rollout work.