{
  "entrypoint": {
    "entrypointKey": "app-generation",
    "instructionSetId": "aqteron.app-generation",
    "instructionReleaseId": "aqteron.app-generation@0.2.20-rc.1",
    "updatedAt": "2026-09-22T04:20:00.000Z",
    "updatedBy": "block14-reliability-production",
    "reason": "Block 14 realtime/call reliability production activation"
  },
  "instructionSet": {
    "instructionSetId": "aqteron.app-generation",
    "setKey": "aqteron.app-generation",
    "displayName": "Aqteron App Generation",
    "description": "Repository draft seed for Aqteron Builder app-generation instructions.",
    "metadataJson": "{\"status\":\"draft\",\"version\":\"0.2.20\",\"contract\":\"Aqteron PWA v1\",\"runtimeSourceOfTruth\":\"aqteron_server_database\",\"repositoryRole\":\"development_seed_export_snapshot\",\"registryMode\":\"database_discovery\",\"architecture\":\"SERVER_INSTRUCTION_ARCHITECTURE.md\",\"bootstrapDraft\":\"BOOTSTRAP.md\",\"capabilityPreflight\":{\"schemaVersion\":\"aqteron.capability_preflight_handoff.v1\",\"cabinetPath\":\"/cabinet/apps\",\"hashRoute\":\"capability-preflight\",\"capabilityIdParameter\":\"id\",\"maxCapabilityIds\":50,\"maxCapabilityIdLength\":128,\"authenticated\":true},\"sourcePath\":\"instruction-set.json\",\"generationHandoff\":{\"schemaVersion\":\"aqteron.generation_handoff.v1\",\"responseSchemaVersion\":\"aqteron.generation_handoff_response.v1\",\"capabilitySnapshotSchemaVersion\":\"aqteron.account_capability_snapshot.v1\",\"authenticatedAccountRequired\":true,\"accountSpecific\":true,\"authorizationSemantics\":\"composition_data_only\",\"finalAuthority\":[\"upload_validation\",\"runtime_validation\"],\"allCapabilitiesRequest\":{\"method\":\"GET\",\"endpoint\":\"/api/me/generation-handoff\",\"scope\":\"all_generation_capabilities\"},\"exactCapabilitySetRequest\":{\"method\":\"POST\",\"endpoint\":\"/api/me/generation-handoff\",\"scope\":\"exact_capability_set\",\"capabilityIdsRequired\":true,\"emptyCapabilityIdsValid\":true,\"requiredBeforeFinalZip\":true},\"freshness\":{\"checkedAtRequired\":true,\"expiresAtRequired\":true,\"refreshWhenExpired\":true},\"fallbackMode\":\"none\"},\"generationContext\":{\"schemaVersion\":\"aqteron.ai_generation_context.v1\",\"deliveryMode\":\"official_server_resolved_locator\",\"authenticatedAccountPresenceSatisfied\":true,\"embeddedCapabilityPreflight\":true,\"secondManualAccountHandoffRequired\":false,\"zeroCapabilityGenerationAllowed\":true,\"arbitraryPastedJsonAccepted\":false,\"publicDiscoverySatisfiesAccountGate\":false,\"legacyNonContextGate\":\"authenticated_snapshot_or_exact_preflight\",\"capabilitySelectionMode\":\"choose_only_generation_usable_with_included_module\",\"responseLanguageHint\":\"cabinet_locale_overridden_by_newer_substantive_user_language\",\"managedFilesPolicy\":\"select_app_files_for_private_server_backed_files_without_silent_local_fallback\",\"snapshotNotAuthorization\":true,\"uploadRuntimeRevalidationRequired\":true,\"appUsersPolicy\":\"select_app_users_for_app_local_identity_without_custom_auth_or_aqteron_account_coupling\",\"trustedAppUserCapabilityBindingPolicy\":\"when app_users@1 is selected, bind per-user managed capability authority only to server-trusted app-user session state; never client-selected user identity\",\"realtimeEventsPolicy\":\"select_realtime_events_for_short_lived_live_update_signals_with_bounded_replay_and_server_derived_app_user_scope\",\"realtimeReliabilityPolicy\":\"reconnect long-poll with one in-flight request, bounded exponential backoff and preserved cursors; never republish replay or presence merely because transport reconnects\",\"managedTurnPolicy\":\"for WebRTC, obtain ICE servers only from the Aqteron helper; managed TURN credentials are short-lived, server-issued, app/environment-bound, never embedded or persisted\",\"webrtcRecoveryPolicy\":\"keep resume tokens volatile; use bounded participant resume/heartbeat retries, preserve signaling cursors, refresh ICE on recovery and never blind-retry non-idempotent signal sends\",\"secretsPolicy\":\"select app_secrets only for server-held named credential references; never embed or expose raw secret values\",\"externalApiProxyPolicy\":\"select external_api_proxy only for explicitly allowlisted HTTPS APIs with bounded methods, sizes, timeouts and quotas\",\"webhooksPolicy\":\"select app_webhooks only for signed bounded inbound JSON events using server-held signing references\",\"jobsPolicy\":\"select app_jobs only for bounded delayed/retryable external API actions; never raw credentials or arbitrary backend code\"}}",
    "metadata": {
      "status": "draft",
      "version": "0.2.20",
      "contract": "Aqteron PWA v1",
      "runtimeSourceOfTruth": "aqteron_server_database",
      "repositoryRole": "development_seed_export_snapshot",
      "registryMode": "database_discovery",
      "architecture": "SERVER_INSTRUCTION_ARCHITECTURE.md",
      "bootstrapDraft": "BOOTSTRAP.md",
      "capabilityPreflight": {
        "schemaVersion": "aqteron.capability_preflight_handoff.v1",
        "cabinetPath": "/cabinet/apps",
        "hashRoute": "capability-preflight",
        "capabilityIdParameter": "id",
        "maxCapabilityIds": 50,
        "maxCapabilityIdLength": 128,
        "authenticated": true
      },
      "sourcePath": "instruction-set.json",
      "generationHandoff": {
        "schemaVersion": "aqteron.generation_handoff.v1",
        "responseSchemaVersion": "aqteron.generation_handoff_response.v1",
        "capabilitySnapshotSchemaVersion": "aqteron.account_capability_snapshot.v1",
        "authenticatedAccountRequired": true,
        "accountSpecific": true,
        "authorizationSemantics": "composition_data_only",
        "finalAuthority": [
          "upload_validation",
          "runtime_validation"
        ],
        "allCapabilitiesRequest": {
          "method": "GET",
          "endpoint": "/api/me/generation-handoff",
          "scope": "all_generation_capabilities"
        },
        "exactCapabilitySetRequest": {
          "method": "POST",
          "endpoint": "/api/me/generation-handoff",
          "scope": "exact_capability_set",
          "capabilityIdsRequired": true,
          "emptyCapabilityIdsValid": true,
          "requiredBeforeFinalZip": true
        },
        "freshness": {
          "checkedAtRequired": true,
          "expiresAtRequired": true,
          "refreshWhenExpired": true
        },
        "fallbackMode": "none"
      },
      "generationContext": {
        "schemaVersion": "aqteron.ai_generation_context.v1",
        "deliveryMode": "official_server_resolved_locator",
        "authenticatedAccountPresenceSatisfied": true,
        "embeddedCapabilityPreflight": true,
        "secondManualAccountHandoffRequired": false,
        "zeroCapabilityGenerationAllowed": true,
        "arbitraryPastedJsonAccepted": false,
        "publicDiscoverySatisfiesAccountGate": false,
        "legacyNonContextGate": "authenticated_snapshot_or_exact_preflight",
        "capabilitySelectionMode": "choose_only_generation_usable_with_included_module",
        "responseLanguageHint": "cabinet_locale_overridden_by_newer_substantive_user_language",
        "managedFilesPolicy": "select_app_files_for_private_server_backed_files_without_silent_local_fallback",
        "snapshotNotAuthorization": true,
        "uploadRuntimeRevalidationRequired": true,
        "appUsersPolicy": "select_app_users_for_app_local_identity_without_custom_auth_or_aqteron_account_coupling",
        "trustedAppUserCapabilityBindingPolicy": "when app_users@1 is selected, bind per-user managed capability authority only to server-trusted app-user session state; never client-selected user identity",
        "realtimeEventsPolicy": "select_realtime_events_for_short_lived_live_update_signals_with_bounded_replay_and_server_derived_app_user_scope",
        "realtimeReliabilityPolicy": "reconnect long-poll with one in-flight request, bounded exponential backoff and preserved cursors; never republish replay or presence merely because transport reconnects",
        "managedTurnPolicy": "for WebRTC, obtain ICE servers only from the Aqteron helper; managed TURN credentials are short-lived, server-issued, app/environment-bound, never embedded or persisted",
        "webrtcRecoveryPolicy": "keep resume tokens volatile; use bounded participant resume/heartbeat retries, preserve signaling cursors, refresh ICE on recovery and never blind-retry non-idempotent signal sends",
        "secretsPolicy": "select app_secrets only for server-held named credential references; never embed or expose raw secret values",
        "externalApiProxyPolicy": "select external_api_proxy only for explicitly allowlisted HTTPS APIs with bounded methods, sizes, timeouts and quotas",
        "webhooksPolicy": "select app_webhooks only for signed bounded inbound JSON events using server-held signing references",
        "jobsPolicy": "select app_jobs only for bounded delayed/retryable external API actions; never raw credentials or arbitrary backend code"
      }
    },
    "createdAt": "2026-08-09T00:00:00.000Z",
    "updatedAt": "2026-08-09T00:00:00.000Z"
  },
  "release": {
    "instructionReleaseId": "aqteron.app-generation@0.2.20-rc.1",
    "instructionSetId": "aqteron.app-generation",
    "releaseKey": "0.2.20-rc.1",
    "releaseStatus": "published",
    "metadataJson": "{\"taskId\":\"BLOCK14-REALTIME-CALL-RELIABILITY\",\"releaseVersion\":\"0.2.20-rc.1\",\"immutableComposition\":true,\"active\":false,\"published\":false,\"instructionSet\":{\"id\":\"aqteron.app-generation\",\"key\":\"aqteron.app-generation\",\"version\":\"0.2.20\",\"status\":\"draft\",\"contract\":\"Aqteron PWA v1\",\"runtimeSourceOfTruth\":\"aqteron_server_database\",\"sourceMetadata\":{\"status\":\"draft\",\"version\":\"0.2.20\",\"contract\":\"Aqteron PWA v1\",\"runtimeSourceOfTruth\":\"aqteron_server_database\",\"repositoryRole\":\"development_seed_export_snapshot\",\"registryMode\":\"database_discovery\",\"architecture\":\"SERVER_INSTRUCTION_ARCHITECTURE.md\",\"bootstrapDraft\":\"BOOTSTRAP.md\",\"capabilityPreflight\":{\"schemaVersion\":\"aqteron.capability_preflight_handoff.v1\",\"cabinetPath\":\"/cabinet/apps\",\"hashRoute\":\"capability-preflight\",\"capabilityIdParameter\":\"id\",\"maxCapabilityIds\":50,\"maxCapabilityIdLength\":128,\"authenticated\":true},\"sourcePath\":\"instruction-set.json\",\"generationHandoff\":{\"schemaVersion\":\"aqteron.generation_handoff.v1\",\"responseSchemaVersion\":\"aqteron.generation_handoff_response.v1\",\"capabilitySnapshotSchemaVersion\":\"aqteron.account_capability_snapshot.v1\",\"authenticatedAccountRequired\":true,\"accountSpecific\":true,\"authorizationSemantics\":\"composition_data_only\",\"finalAuthority\":[\"upload_validation\",\"runtime_validation\"],\"allCapabilitiesRequest\":{\"method\":\"GET\",\"endpoint\":\"/api/me/generation-handoff\",\"scope\":\"all_generation_capabilities\"},\"exactCapabilitySetRequest\":{\"method\":\"POST\",\"endpoint\":\"/api/me/generation-handoff\",\"scope\":\"exact_capability_set\",\"capabilityIdsRequired\":true,\"emptyCapabilityIdsValid\":true,\"requiredBeforeFinalZip\":true},\"freshness\":{\"checkedAtRequired\":true,\"expiresAtRequired\":true,\"refreshWhenExpired\":true},\"fallbackMode\":\"none\"},\"generationContext\":{\"schemaVersion\":\"aqteron.ai_generation_context.v1\",\"deliveryMode\":\"official_server_resolved_locator\",\"authenticatedAccountPresenceSatisfied\":true,\"embeddedCapabilityPreflight\":true,\"secondManualAccountHandoffRequired\":false,\"zeroCapabilityGenerationAllowed\":true,\"arbitraryPastedJsonAccepted\":false,\"publicDiscoverySatisfiesAccountGate\":false,\"legacyNonContextGate\":\"authenticated_snapshot_or_exact_preflight\",\"capabilitySelectionMode\":\"choose_only_generation_usable_with_included_module\",\"responseLanguageHint\":\"cabinet_locale_overridden_by_newer_substantive_user_language\",\"managedFilesPolicy\":\"select_app_files_for_private_server_backed_files_without_silent_local_fallback\",\"snapshotNotAuthorization\":true,\"uploadRuntimeRevalidationRequired\":true,\"appUsersPolicy\":\"select_app_users_for_app_local_identity_without_custom_auth_or_aqteron_account_coupling\",\"trustedAppUserCapabilityBindingPolicy\":\"when app_users@1 is selected, bind per-user managed capability authority only to server-trusted app-user session state; never client-selected user identity\",\"realtimeEventsPolicy\":\"select_realtime_events_for_short_lived_live_update_signals_with_bounded_replay_and_server_derived_app_user_scope\",\"realtimeReliabilityPolicy\":\"reconnect long-poll with one in-flight request, bounded exponential backoff and preserved cursors; never republish replay or presence merely because transport reconnects\",\"managedTurnPolicy\":\"for WebRTC, obtain ICE servers only from the Aqteron helper; managed TURN credentials are short-lived, server-issued, app/environment-bound, never embedded or persisted\",\"webrtcRecoveryPolicy\":\"keep resume tokens volatile; use bounded participant resume/heartbeat retries, preserve signaling cursors, refresh ICE on recovery and never blind-retry non-idempotent signal sends\",\"secretsPolicy\":\"select app_secrets only for server-held named credential references; never embed or expose raw secret values\",\"externalApiProxyPolicy\":\"select external_api_proxy only for explicitly allowlisted HTTPS APIs with bounded methods, sizes, timeouts and quotas\",\"webhooksPolicy\":\"select app_webhooks only for signed bounded inbound JSON events using server-held signing references\",\"jobsPolicy\":\"select app_jobs only for bounded delayed/retryable external API actions; never raw credentials or arbitrary backend code\"}}},\"modulePins\":[{\"instructionModuleId\":\"aqteron.builder.core\",\"moduleKey\":\"aqteron.builder.core\",\"moduleKind\":\"core\",\"sourcePath\":\"BUILDER_CORE.md\",\"instructionModuleVersionId\":\"aqteron.builder.core@0.2.6\",\"versionLabel\":\"0.2.6\",\"contentSha256\":\"c15131e44427fb0f47a422e4fa46e7c1da75ddec0848b8a5d7a8c1eb0d62f8aa\",\"status\":\"draft\",\"contract\":\"Aqteron PWA v1\",\"selectionMetadata\":null,\"capabilityAvailability\":null,\"selfCheckMetadata\":null},{\"instructionModuleId\":\"aqteron.capability.app_database@1\",\"moduleKey\":\"aqteron.capability.app_database@1\",\"moduleKind\":\"capability\",\"sourcePath\":\"capabilities/APP_DATABASE.md\",\"instructionModuleVersionId\":\"aqteron.capability.app_database@1@0.1.5\",\"versionLabel\":\"0.1.5\",\"contentSha256\":\"52e1ab38d67951ff4c4840fd0212ac1bf86a4f883d218d20d3589564c6caa2f6\",\"status\":\"draft\",\"contract\":\"Aqteron PWA v1\",\"selectionMetadata\":{\"schemaVersion\":\"aqteron.builder.selection_metadata.v1\",\"summary\":\"App-scoped JSON record storage for shared or cross-device persistence.\",\"userNeeds\":[\"persist structured records beyond one browser or install\",\"share app-scoped records across linked users or devices\",\"store bounded server-side JSON records\"],\"selectionSignals\":[\"localStorage or IndexedDB is insufficient\",\"records must survive reinstall or device changes\",\"multiple users or devices need the same app data\"],\"exclusions\":[\"file, image, document, or attachment storage\",\"raw SQL or arbitrary backend database access\",\"secrets, credentials, passwords, tokens, or private keys\"],\"dependencies\":[],\"compatibility\":{\"contracts\":[\"Aqteron PWA v1\"],\"requires\":[],\"conflicts\":[]},\"runtime\":{\"adapterId\":\"app_database@1\"},\"availability\":{\"instructionStatus\":\"draft\",\"registryStatus\":\"available\",\"runtimeStatus\":\"runtime_available\",\"builderSelectable\":true,\"instructionVisible\":true,\"entitlementAuthority\":\"aqteron_validator_runtime\",\"notSelectableReason\":null}},\"capabilityAvailability\":{\"capabilityKey\":\"app_database@1\",\"registryStatus\":\"available\",\"runtimeStatus\":\"runtime_available\",\"builderSelectable\":true,\"instructionVisible\":true,\"entitlementAuthority\":\"aqteron_validator_runtime\"},\"selfCheckMetadata\":{\"schemaVersion\":\"aqteron.builder.module_self_check.v1\",\"instructionModuleId\":\"aqteron.capability.app_database@1\",\"moduleKind\":\"capability\",\"required\":true,\"appliesWhenSelected\":true,\"sourceHeading\":\"Module self-check\",\"checks\":[{\"id\":\"declared_when_helper_used\",\"text\":\"capability is declared when JavaScript uses `appDatabase`\"},{\"id\":\"used_collections_declared\",\"text\":\"every used collection is declared\"},{\"id\":\"schema_keys_match\",\"text\":\"schema and JS keys are identical lower_snake_case ASCII\"},{\"id\":\"no_undeclared_fields\",\"text\":\"no undeclared extra fields are written\"},{\"id\":\"new_record_uses_put\",\"text\":\"every new logical record uses `put` with declared `record.create`\"},{\"id\":\"existing_record_uses_set\",\"text\":\"every existing logical record update uses `set` with declared `record.update`\"},{\"id\":\"offline_replay_preserves_intent\",\"text\":\"offline/deferred replay preserves `put` versus `set` operation intent\"},{\"id\":\"bounded_list_limit\",\"text\":\"every `list` call has an explicit numeric limit from 1 to 100\"},{\"id\":\"db_list_limit_not_record_quota\",\"text\":\"a `list` retrieval limit is not treated as the collection `maxRecords` quota\"},{\"id\":\"no_raw_secrets\",\"text\":\"no raw secrets are persisted\"},{\"id\":\"no_private_database_routes\",\"text\":\"no direct/private database routes or raw SQL are used\"},{\"id\":\"app_user_server_authority\",\"text\":\"when `authMode: \\\"app_user\\\"` is selected, `app_users@1` is enabled and authorization comes only from the trusted server-resolved app-user session\"},{\"id\":\"no_client_identity_or_row_privacy_claim\",\"text\":\"no client-supplied user identity is treated as authority and no row-level privacy is claimed from `authMode` alone\"},{\"id\":\"user_readable_errors\",\"text\":\"capability failures produce user-readable UI errors\"}]}},{\"instructionModuleId\":\"aqteron.capability.app_files@1\",\"moduleKey\":\"aqteron.capability.app_files@1\",\"moduleKind\":\"capability\",\"sourcePath\":\"capabilities/APP_FILES.md\",\"instructionModuleVersionId\":\"aqteron.capability.app_files@1@0.3.1\",\"versionLabel\":\"0.3.1\",\"contentSha256\":\"3c184d3714879bedcbdb009e553667034902170d6677589b2b5d05f4bfb14541\",\"status\":\"activation_candidate\",\"contract\":\"Aqteron PWA v1\",\"selectionMetadata\":{\"schemaVersion\":\"aqteron.builder.selection_metadata.v1\",\"summary\":\"Guarded private file storage for entitled applications when canonical readiness controls pass.\",\"userNeeds\":[\"store user files, attachments, images, documents, imports, or exports\",\"keep private application-scoped files in managed storage\",\"associate files with app workflows\"],\"selectionSignals\":[\"managed private files are required and server-side entitlement is available\",\"files must persist outside local browser storage\",\"workflow references uploaded or generated files\"],\"exclusions\":[\"workflows that can remain entirely in local browser storage\",\"public hosting or public URL generation\",\"shared-drive behavior across unrelated apps or users\",\"structured JSON record storage without files\"],\"dependencies\":[],\"compatibility\":{\"contracts\":[\"Aqteron PWA v1\"],\"requires\":[],\"conflicts\":[]},\"runtime\":{\"adapterId\":\"app_files@1\"},\"availability\":{\"instructionStatus\":\"activation_candidate\",\"registryStatus\":\"available\",\"runtimeStatus\":\"runtime_available\",\"builderSelectable\":true,\"instructionVisible\":true,\"entitlementAuthority\":\"aqteron_validator_runtime\",\"notSelectableReason\":null}},\"capabilityAvailability\":{\"capabilityKey\":\"app_files@1\",\"registryStatus\":\"available\",\"runtimeStatus\":\"runtime_available\",\"builderSelectable\":true,\"instructionVisible\":true,\"entitlementAuthority\":\"aqteron_validator_runtime\"},\"selfCheckMetadata\":{\"schemaVersion\":\"aqteron.builder.module_self_check.v1\",\"instructionModuleId\":\"aqteron.capability.app_files@1\",\"moduleKind\":\"capability\",\"required\":true,\"appliesWhenSelected\":true,\"sourceHeading\":\"Module self-check\",\"checks\":[{\"id\":\"declared_when_helper_used\",\"text\":\"capability is declared if `appFiles` is used\"},{\"id\":\"only_prompt2app_helper\",\"text\":\"only the exact `window.Prompt2App.appFiles` methods above are used\"},{\"id\":\"subject_mode_identity_matches\",\"text\":\"identity handling matches the declared subject mode: `app_user` requires trusted app-local sign-in, `app` does not account-link, and only legacy no-`subjectMode` declarations may call `connectAccount()`\"},{\"id\":\"no_client_file_identity_authority\",\"text\":\"no client-provided user/subject identifier is used as file authorization authority\"},{\"id\":\"used_buckets_declared_private\",\"text\":\"every used bucket is declared and private\"},{\"id\":\"file_quota_dimensions_coherent\",\"text\":\"MIME types are bounded and `maxFileSizeBytes`, `maxTotalBytes`, and `maxFiles` are validated as separate dimensions within their exact ceilings\"},{\"id\":\"mixed_db_files_fixture_coherent\",\"text\":\"mixed database/file workflows keep database `list` limits, database `maxRecords`, and file `maxFiles` distinct and dimensionally coherent\"},{\"id\":\"exact_file_transport\",\"text\":\"file inputs are browser `File` values and downloads use `contentBase64`\"},{\"id\":\"no_invented_storage_authority\",\"text\":\"no public/presigned/storage URLs, filesystem paths, internal metadata, or unsupported sharing are invented\"},{\"id\":\"server_entitlement_authority\",\"text\":\"server entitlement is never inferred from the package\"},{\"id\":\"visible_errors\",\"text\":\"errors are visible and do not falsely report successful storage\"}]}},{\"instructionModuleId\":\"aqteron.capability.app_jobs@1\",\"moduleKey\":\"aqteron.capability.app_jobs@1\",\"moduleKind\":\"capability\",\"sourcePath\":\"capabilities/APP_JOBS.md\",\"instructionModuleVersionId\":\"aqteron.capability.app_jobs@1@0.1.0\",\"versionLabel\":\"0.1.0\",\"contentSha256\":\"bbecf7d4dbb15939472be98dc253825c383cce1a7030ca62cd68c283903c84d6\",\"status\":\"draft\",\"contract\":\"Aqteron PWA v1\",\"selectionMetadata\":{\"schemaVersion\":\"aqteron.builder.selection_metadata.v1\",\"summary\":\"Bounded delayed and retryable external API actions executed by a managed worker.\",\"userNeeds\":[\"run an approved external API action later\",\"retry transient external API failures with bounded backoff\",\"inspect and cancel pending managed jobs\"],\"selectionSignals\":[\"the scheduled work is representable as an external_api_proxy request descriptor\",\"one-time delayed execution and bounded retries are sufficient\"],\"exclusions\":[\"arbitrary code execution, cron scripts, unbounded recurring tasks, raw secrets in payloads, or custom background servers\"],\"dependencies\":[\"external_api_proxy@1\",\"app_secrets@1\"],\"compatibility\":{\"contracts\":[\"Aqteron PWA v1\"],\"requires\":[\"external_api_proxy@1\",\"app_secrets@1\"],\"conflicts\":[]},\"runtime\":{\"adapterId\":\"app_jobs@1\"},\"availability\":{\"instructionStatus\":\"draft\",\"registryStatus\":\"available\",\"runtimeStatus\":\"runtime_available\",\"builderSelectable\":true,\"instructionVisible\":true,\"entitlementAuthority\":\"aqteron_validator_runtime\",\"notSelectableReason\":null}},\"capabilityAvailability\":{\"capabilityKey\":\"app_jobs@1\",\"registryStatus\":\"available\",\"runtimeStatus\":\"runtime_available\",\"builderSelectable\":true,\"instructionVisible\":true,\"entitlementAuthority\":\"aqteron_validator_runtime\"},\"selfCheckMetadata\":{\"schemaVersion\":\"aqteron.builder.module_self_check.v1\",\"instructionModuleId\":\"aqteron.capability.app_jobs@1\",\"moduleKind\":\"capability\",\"required\":true,\"appliesWhenSelected\":true,\"sourceHeading\":\"Module self-check\",\"checks\":[{\"id\":\"dependencies_declared\",\"text\":\"`external_api_proxy@1` and required `app_secrets@1` references are declared\"},{\"id\":\"request_allowlisted\",\"text\":\"every scheduled request satisfies the declared external API domain and method allowlist\"},{\"id\":\"bounded_schedule\",\"text\":\"run time, queue size, retry count, and retry delay stay inside declared bounds\"},{\"id\":\"idempotency_key\",\"text\":\"each logical scheduled action uses a stable non-secret idempotency key\"},{\"id\":\"no_raw_credentials\",\"text\":\"scheduled job payloads contain no raw credentials or arbitrary backend code\"},{\"id\":\"app_user_dependency\",\"text\":\"`authMode: \\\"app_user\\\"` also declares enabled `app_users@1`\"},{\"id\":\"managed_helper_only\",\"text\":\"generated code uses only the managed job status/schedule/list/get/cancel helpers\"}]}},{\"instructionModuleId\":\"aqteron.capability.app_secrets@1\",\"moduleKey\":\"aqteron.capability.app_secrets@1\",\"moduleKind\":\"capability\",\"sourcePath\":\"capabilities/APP_SECRETS.md\",\"instructionModuleVersionId\":\"aqteron.capability.app_secrets@1@0.1.0\",\"versionLabel\":\"0.1.0\",\"contentSha256\":\"f1b161d9d941227f90feeebc9634838384b36de590e756fa813c5e44b1509fd6\",\"status\":\"draft\",\"contract\":\"Aqteron PWA v1\",\"selectionMetadata\":{\"schemaVersion\":\"aqteron.builder.selection_metadata.v1\",\"summary\":\"Server-held encrypted credential references that are never exposed to generated app JavaScript.\",\"userNeeds\":[\"store third-party API credentials without exposing them to browser code\",\"let the app owner configure named server-held credential references\",\"rotate or revoke integration credentials without rebuilding the application\"],\"selectionSignals\":[\"an external integration needs an API key, token, or signing secret\",\"the credential must remain server-side\",\"the user can configure the credential after publication\"],\"exclusions\":[\"embedding raw credentials in ZIP files, metadata, JavaScript, browser storage, logs, or job payloads\",\"using app_secrets as general user data storage\"],\"dependencies\":[],\"compatibility\":{\"contracts\":[\"Aqteron PWA v1\"],\"requires\":[],\"conflicts\":[]},\"runtime\":{\"adapterId\":\"app_secrets@1\"},\"availability\":{\"instructionStatus\":\"draft\",\"registryStatus\":\"available\",\"runtimeStatus\":\"runtime_available\",\"builderSelectable\":true,\"instructionVisible\":true,\"entitlementAuthority\":\"aqteron_validator_runtime\",\"notSelectableReason\":null}},\"capabilityAvailability\":{\"capabilityKey\":\"app_secrets@1\",\"registryStatus\":\"available\",\"runtimeStatus\":\"runtime_available\",\"builderSelectable\":true,\"instructionVisible\":true,\"entitlementAuthority\":\"aqteron_validator_runtime\"},\"selfCheckMetadata\":{\"schemaVersion\":\"aqteron.builder.module_self_check.v1\",\"instructionModuleId\":\"aqteron.capability.app_secrets@1\",\"moduleKind\":\"capability\",\"required\":true,\"appliesWhenSelected\":true,\"sourceHeading\":\"Module self-check\",\"checks\":[{\"id\":\"declared_when_needed\",\"text\":\"`app_secrets@1` is declared whenever server-held integration credentials are required\"},{\"id\":\"refs_declared\",\"text\":\"every credential reference used by another capability is declared in `config.refs`\"},{\"id\":\"no_raw_secret_in_package\",\"text\":\"no raw secret value appears in ZIP files, metadata, JavaScript, browser storage, logs, webhook payloads, or job payloads\"},{\"id\":\"status_only_browser\",\"text\":\"generated app code uses only status visibility and never expects a raw secret value\"},{\"id\":\"owner_configuration\",\"text\":\"the user-facing flow explains that the application owner configures the credential in Aqteron\"},{\"id\":\"rotation_safe\",\"text\":\"rotation or revocation does not require rebuilding the generated application\"}]}},{\"instructionModuleId\":\"aqteron.capability.app_users@1\",\"moduleKey\":\"aqteron.capability.app_users@1\",\"moduleKind\":\"capability\",\"sourcePath\":\"capabilities/APP_USERS.md\",\"instructionModuleVersionId\":\"aqteron.capability.app_users@1@0.1.1\",\"versionLabel\":\"0.1.1\",\"contentSha256\":\"39de99146570c81ada8d019b085101d83f86d6ec03dccb3cace5a3a363c96dab\",\"status\":\"draft\",\"contract\":\"Aqteron PWA v1\",\"selectionMetadata\":{\"schemaVersion\":\"aqteron.builder.selection_metadata.v1\",\"summary\":\"Isolated application-local user accounts, sessions, roles, permissions, and credential recovery.\",\"userNeeds\":[\"let visitors create or use accounts that belong only to the application\",\"maintain application-local sign-in sessions across visits\",\"check application-local roles or permissions\"],\"selectionSignals\":[\"the requested workflow needs sign-in that must not depend on Aqteron platform accounts\",\"multiple end users need distinct identities inside one published application\",\"managed credential hashing, lockout, recovery, or session revocation is required\"],\"exclusions\":[\"Aqteron platform account authentication or account linking\",\"custom authentication servers or direct credential storage\",\"workflows that need no user identity\"],\"dependencies\":[],\"compatibility\":{\"contracts\":[\"Aqteron PWA v1\"],\"requires\":[],\"conflicts\":[]},\"runtime\":{\"adapterId\":\"app_users@1\"},\"availability\":{\"instructionStatus\":\"draft\",\"registryStatus\":\"available\",\"runtimeStatus\":\"runtime_available\",\"builderSelectable\":true,\"instructionVisible\":true,\"entitlementAuthority\":\"aqteron_validator_runtime\",\"notSelectableReason\":null}},\"capabilityAvailability\":{\"capabilityKey\":\"app_users@1\",\"registryStatus\":\"available\",\"runtimeStatus\":\"runtime_available\",\"builderSelectable\":true,\"instructionVisible\":true,\"entitlementAuthority\":\"aqteron_validator_runtime\"},\"selfCheckMetadata\":{\"schemaVersion\":\"aqteron.builder.module_self_check.v1\",\"instructionModuleId\":\"aqteron.capability.app_users@1\",\"moduleKind\":\"capability\",\"required\":true,\"appliesWhenSelected\":true,\"sourceHeading\":\"Module self-check\",\"checks\":[{\"id\":\"declared_when_helper_used\",\"text\":\"`app_users@1` is declared whenever `appUsers` is used\"},{\"id\":\"supported_methods_only\",\"text\":\"only the exact `window.Prompt2App.appUsers` public methods above are used\"},{\"id\":\"platform_identity_separate\",\"text\":\"app users are never treated as Aqteron platform accounts\"},{\"id\":\"no_custom_auth_backend\",\"text\":\"no custom authentication backend or private app-user route is invented\"},{\"id\":\"no_raw_auth_secrets\",\"text\":\"raw passwords, PINs, recovery codes, session tokens, and cookies are never persisted by generated code\"},{\"id\":\"registration_mode_matches\",\"text\":\"registration UI matches the declared `registrationMode`\"},{\"id\":\"bounded_security_policy\",\"text\":\"credential types and session/lockout bounds match the declaration contract\"},{\"id\":\"permission_boundary\",\"text\":\"permission checks do not rely on hiding UI as server authorization\"},{\"id\":\"admin_ops_not_public\",\"text\":\"role assignment and recovery-code issuance are not exposed as public browser operations\"},{\"id\":\"trusted_cross_capability_authority\",\"text\":\"capability combinations that require app-user authority derive it only from the trusted server session and never from client-selected user IDs\"},{\"id\":\"current_binding_modes\",\"text\":\"per-user files use `subjectMode: \\\"app_user\\\"`, database sign-in gates use `authMode: \\\"app_user\\\"`, and push does not account-link when `app_users@1` is enabled\"},{\"id\":\"visible_auth_states\",\"text\":\"authentication, lockout, recovery, and unavailable states are shown clearly to the user\"}]}},{\"instructionModuleId\":\"aqteron.capability.app_webhooks@1\",\"moduleKey\":\"aqteron.capability.app_webhooks@1\",\"moduleKind\":\"capability\",\"sourcePath\":\"capabilities/APP_WEBHOOKS.md\",\"instructionModuleVersionId\":\"aqteron.capability.app_webhooks@1@0.1.0\",\"versionLabel\":\"0.1.0\",\"contentSha256\":\"ce9424ebce6996b5f6e3ef31ea7eb644e83644f2c46bcc22c01acede164749f1\",\"status\":\"draft\",\"contract\":\"Aqteron PWA v1\",\"selectionMetadata\":{\"schemaVersion\":\"aqteron.builder.selection_metadata.v1\",\"summary\":\"Verified bounded inbound JSON webhook events isolated per Application Environment.\",\"userNeeds\":[\"receive signed events from an external provider\",\"consume bounded verified JSON callbacks\",\"avoid exposing webhook signing material to browser code\"],\"selectionSignals\":[\"the provider can send HMAC-SHA256 signed JSON to a stable app webhook endpoint\",\"bounded retention and polling are sufficient\"],\"exclusions\":[\"unsigned callbacks, arbitrary request bodies, raw credential transport, or custom webhook servers\"],\"dependencies\":[\"app_secrets@1\"],\"compatibility\":{\"contracts\":[\"Aqteron PWA v1\"],\"requires\":[\"app_secrets@1\"],\"conflicts\":[]},\"runtime\":{\"adapterId\":\"app_webhooks@1\"},\"availability\":{\"instructionStatus\":\"draft\",\"registryStatus\":\"available\",\"runtimeStatus\":\"runtime_available\",\"builderSelectable\":true,\"instructionVisible\":true,\"entitlementAuthority\":\"aqteron_validator_runtime\",\"notSelectableReason\":null}},\"capabilityAvailability\":{\"capabilityKey\":\"app_webhooks@1\",\"registryStatus\":\"available\",\"runtimeStatus\":\"runtime_available\",\"builderSelectable\":true,\"instructionVisible\":true,\"entitlementAuthority\":\"aqteron_validator_runtime\"},\"selfCheckMetadata\":{\"schemaVersion\":\"aqteron.builder.module_self_check.v1\",\"instructionModuleId\":\"aqteron.capability.app_webhooks@1\",\"moduleKind\":\"capability\",\"required\":true,\"appliesWhenSelected\":true,\"sourceHeading\":\"Module self-check\",\"checks\":[{\"id\":\"declared_hook\",\"text\":\"every webhook consumed by the app has a declared safe hook ID\"},{\"id\":\"signing_ref_declared\",\"text\":\"every hook signing reference exists in `app_secrets@1`\"},{\"id\":\"bounded_inbound\",\"text\":\"body size, retention, and event count are bounded\"},{\"id\":\"verified_events_only\",\"text\":\"browser code consumes only verified events through managed status/poll/ack helpers\"},{\"id\":\"no_signing_secret_exposure\",\"text\":\"signing secrets are never embedded or returned to browser code\"},{\"id\":\"app_user_dependency\",\"text\":\"`authMode: \\\"app_user\\\"` also declares enabled `app_users@1` when used\"}]}},{\"instructionModuleId\":\"aqteron.capability.external_api_proxy@1\",\"moduleKey\":\"aqteron.capability.external_api_proxy@1\",\"moduleKind\":\"capability\",\"sourcePath\":\"capabilities/EXTERNAL_API_PROXY.md\",\"instructionModuleVersionId\":\"aqteron.capability.external_api_proxy@1@0.1.0\",\"versionLabel\":\"0.1.0\",\"contentSha256\":\"8b7dd25ec8359daedc3e7b7567d87b322054cbda9f24f13697ef435d3e9623e7\",\"status\":\"draft\",\"contract\":\"Aqteron PWA v1\",\"selectionMetadata\":{\"schemaVersion\":\"aqteron.builder.selection_metadata.v1\",\"summary\":\"Allowlisted bounded HTTPS calls with server-held authentication and SSRF protection.\",\"userNeeds\":[\"call a specific approved external HTTPS API\",\"use server-held authentication for a third-party provider\",\"keep outbound network access bounded and auditable\"],\"selectionSignals\":[\"the workflow explicitly depends on one or more known public API domains\",\"declared methods, body sizes, timeouts, and quotas are sufficient\",\"the provider can be called without arbitrary headers or redirects\"],\"exclusions\":[\"arbitrary internet access, crawling, private/internal URLs, custom ports, raw sockets, or browser automation\",\"client-supplied Authorization/Cookie headers or absolute URLs\"],\"dependencies\":[\"app_secrets@1\"],\"compatibility\":{\"contracts\":[\"Aqteron PWA v1\"],\"requires\":[\"app_secrets@1\"],\"conflicts\":[]},\"runtime\":{\"adapterId\":\"external_api_proxy@1\"},\"availability\":{\"instructionStatus\":\"draft\",\"registryStatus\":\"available\",\"runtimeStatus\":\"runtime_available\",\"builderSelectable\":true,\"instructionVisible\":true,\"entitlementAuthority\":\"aqteron_validator_runtime\",\"notSelectableReason\":null}},\"capabilityAvailability\":{\"capabilityKey\":\"external_api_proxy@1\",\"registryStatus\":\"available\",\"runtimeStatus\":\"runtime_available\",\"builderSelectable\":true,\"instructionVisible\":true,\"entitlementAuthority\":\"aqteron_validator_runtime\"},\"selfCheckMetadata\":{\"schemaVersion\":\"aqteron.builder.module_self_check.v1\",\"instructionModuleId\":\"aqteron.capability.external_api_proxy@1\",\"moduleKind\":\"capability\",\"required\":true,\"appliesWhenSelected\":true,\"sourceHeading\":\"Module self-check\",\"checks\":[{\"id\":\"declared_domain_method\",\"text\":\"every external API domain and HTTP method used by the app is explicitly declared\"},{\"id\":\"server_held_auth\",\"text\":\"authentication uses only declared `app_secrets@1` references\"},{\"id\":\"relative_request_only\",\"text\":\"generated code sends only domain, method, relative path, bounded query, and optional JSON body\"},{\"id\":\"no_client_headers_or_url\",\"text\":\"no absolute URL, arbitrary headers, Authorization/Cookie value, protocol, port, host override, or IP target is client supplied\"},{\"id\":\"bounded_network_limits\",\"text\":\"timeout, request bytes, response bytes, and requests-per-minute quota are declared and bounded\"},{\"id\":\"app_user_dependency\",\"text\":\"`authMode: \\\"app_user\\\"` also declares enabled `app_users@1`\"},{\"id\":\"managed_helper_only\",\"text\":\"generated code uses only the managed external API helper\"}]}},{\"instructionModuleId\":\"aqteron.capability.push_notifications@1\",\"moduleKey\":\"aqteron.capability.push_notifications@1\",\"moduleKind\":\"capability\",\"sourcePath\":\"capabilities/PUSH_NOTIFICATIONS.md\",\"instructionModuleVersionId\":\"aqteron.capability.push_notifications@1@0.1.5\",\"versionLabel\":\"0.1.5\",\"contentSha256\":\"dd8f2a4c793617b37a9afc1ab1fb9d28a515693e4ecc712cb83a594ac6304074\",\"status\":\"draft\",\"contract\":\"Aqteron PWA v1\",\"selectionMetadata\":{\"schemaVersion\":\"aqteron.builder.selection_metadata.v1\",\"summary\":\"Platform-managed push notification subscription and declared trigger support.\",\"userNeeds\":[\"notify users while the installed or browser PWA is closed\",\"support declared message, reminder, or shared-data alerts\",\"let users subscribe, unsubscribe, and manage notification preferences\"],\"selectionSignals\":[\"user explicitly needs push or closed-app alerts\",\"notification trigger fits the supported platform contract\",\"helper-only subscription controls are sufficient\"],\"exclusions\":[\"custom service workers or direct push provider calls\",\"invented send endpoints or arbitrary server triggers\",\"storing browser subscription secrets in app state\"],\"dependencies\":[],\"compatibility\":{\"contracts\":[\"Aqteron PWA v1\"],\"requires\":[],\"conflicts\":[]},\"runtime\":{\"adapterId\":null},\"availability\":{\"instructionStatus\":\"draft\",\"registryStatus\":\"available\",\"runtimeStatus\":\"runtime_available\",\"builderSelectable\":true,\"instructionVisible\":true,\"entitlementAuthority\":\"aqteron_validator_runtime\",\"notSelectableReason\":null}},\"capabilityAvailability\":{\"capabilityKey\":\"push_notifications@1\",\"registryStatus\":\"available\",\"runtimeStatus\":\"runtime_available\",\"builderSelectable\":true,\"instructionVisible\":true,\"entitlementAuthority\":\"aqteron_validator_runtime\"},\"selfCheckMetadata\":{\"schemaVersion\":\"aqteron.builder.module_self_check.v1\",\"instructionModuleId\":\"aqteron.capability.push_notifications@1\",\"moduleKind\":\"capability\",\"required\":true,\"appliesWhenSelected\":true,\"sourceHeading\":\"Module self-check\",\"checks\":[{\"id\":\"declared_when_helper_used\",\"text\":\"`push_notifications@1` is declared when notifications helper is used\"},{\"id\":\"supported_methods_only\",\"text\":\"only supported helper methods are called and no `send()` exists\"},{\"id\":\"no_app_service_worker_or_provider\",\"text\":\"no application service worker or push-provider endpoint is included\"},{\"id\":\"identity_mode_flow\",\"text\":\"identity flow matches the app: with `app_users@1`, push uses the trusted app-user session and never calls `connectAccount()`; without it, legacy account linking and permission remain separate explicit user actions\"},{\"id\":\"no_client_recipient_identity_authority\",\"text\":\"no client-supplied user identity is treated as recipient ownership authority\"},{\"id\":\"declared_database_trigger_fields\",\"text\":\"triggers use declared `app_database.record.create` fields\"},{\"id\":\"push_create_trigger_uses_create_path\",\"text\":\"every `app_database.record.create` trigger record uses the `appDatabase.put` create path, including offline/deferred replay\"},{\"id\":\"bounded_trigger_fields\",\"text\":\"actor/target/click URL fields exist as bounded strings in the database schema\"},{\"id\":\"same_app_click_url\",\"text\":\"click URL is root-relative and same-app\"},{\"id\":\"bounded_non_private_content\",\"text\":\"notification title/body are bounded and do not expose private message contents\"},{\"id\":\"opaque_recipient_ids\",\"text\":\"opaque recipient IDs are not treated as secrets or modified\"}]}},{\"instructionModuleId\":\"aqteron.capability.realtime_events@1\",\"moduleKey\":\"aqteron.capability.realtime_events@1\",\"moduleKind\":\"capability\",\"sourcePath\":\"capabilities/REALTIME_EVENTS.md\",\"instructionModuleVersionId\":\"aqteron.capability.realtime_events@1@0.1.1\",\"versionLabel\":\"0.1.1\",\"contentSha256\":\"6c1d3c59037e07d7bb4228d993f6a4ebecdf04e29d2680e008993e2c63b976e5\",\"status\":\"draft\",\"contract\":\"Aqteron PWA v1\",\"selectionMetadata\":{\"schemaVersion\":\"aqteron.builder.selection_metadata.v1\",\"summary\":\"Bounded app/user-scoped live update signals with reconnect and replay.\",\"userNeeds\":[\"update an already-open app quickly when durable shared state changes\",\"show message/status/read-state/presence changes without manual refresh\",\"replay a bounded window of missed live update signals after reconnect\"],\"selectionSignals\":[\"the workflow has multi-tab, multi-device, or multi-user live updates\",\"durable records remain in app_database@1 while realtime only signals changes\",\"bounded long-poll transport with replay is sufficient\"],\"exclusions\":[\"durable business-data history or unbounded event logs\",\"custom WebSocket/SSE servers or arbitrary backend realtime infrastructure\",\"large payloads, files, credentials, secrets, or raw session/user identity transport\"],\"dependencies\":[],\"compatibility\":{\"contracts\":[\"Aqteron PWA v1\"],\"requires\":[],\"conflicts\":[]},\"runtime\":{\"adapterId\":\"realtime_events@1\"},\"availability\":{\"instructionStatus\":\"draft\",\"registryStatus\":\"available\",\"runtimeStatus\":\"runtime_available\",\"builderSelectable\":true,\"instructionVisible\":true,\"entitlementAuthority\":\"aqteron_validator_runtime\",\"notSelectableReason\":null}},\"capabilityAvailability\":{\"capabilityKey\":\"realtime_events@1\",\"registryStatus\":\"available\",\"runtimeStatus\":\"runtime_available\",\"builderSelectable\":true,\"instructionVisible\":true,\"entitlementAuthority\":\"aqteron_validator_runtime\"},\"selfCheckMetadata\":{\"schemaVersion\":\"aqteron.builder.module_self_check.v1\",\"instructionModuleId\":\"aqteron.capability.realtime_events@1\",\"moduleKind\":\"capability\",\"required\":true,\"appliesWhenSelected\":true,\"sourceHeading\":\"Module self-check\",\"checks\":[{\"id\":\"declared_when_helper_used\",\"text\":\"`realtime_events@1` is declared whenever `realtimeEvents` is used\"},{\"id\":\"supported_methods_only\",\"text\":\"only the exact managed `status`, `publish`, `poll`, and `subscribe` helper methods are used\"},{\"id\":\"channels_types_declared\",\"text\":\"every used channel and event type is declared\"},{\"id\":\"bounded_limits\",\"text\":\"each channel has bounded retention, event count, and payload size within the exact platform limits\"},{\"id\":\"app_user_dependency\",\"text\":\"`app_user` channels also declare enabled `app_users@1`\"},{\"id\":\"no_client_authority\",\"text\":\"no client-supplied app/user/subject/session/storage identifier is used as authorization authority\"},{\"id\":\"durable_data_separate\",\"text\":\"durable business records remain in `app_database@1` or another appropriate durable capability\"},{\"id\":\"cursor_reset_refreshes\",\"text\":\"cursor reset causes an authoritative state refresh instead of guessing missing events\"},{\"id\":\"bounded_subscribe_retry\",\"text\":\"subscribe retry uses a bounded exponential backoff with a single in-flight poll\"},{\"id\":\"no_reconnect_amplification\",\"text\":\"reconnect preserves the cursor and does not republish replay/presence events automatically\"},{\"id\":\"presence_ephemeral\",\"text\":\"presence is treated only as an ephemeral hint\"},{\"id\":\"no_sensitive_payloads\",\"text\":\"realtime payloads contain no secrets, credentials, raw session tokens, files, or large/private record bodies\"}]}},{\"instructionModuleId\":\"aqteron.capability.web_parser@1\",\"moduleKey\":\"aqteron.capability.web_parser@1\",\"moduleKind\":\"capability\",\"sourcePath\":\"capabilities/WEB_PARSER.md\",\"instructionModuleVersionId\":\"aqteron.capability.web_parser@1@0.1.4\",\"versionLabel\":\"0.1.4\",\"contentSha256\":\"3360d11b8d7fd6124694cd83d606eccb68bafe2f697dba915fa655f12c36661a\",\"status\":\"draft\",\"contract\":\"Aqteron PWA v1\",\"selectionMetadata\":{\"schemaVersion\":\"aqteron.builder.selection_metadata.v1\",\"summary\":\"Bounded readable-text parsing for explicitly approved public domains.\",\"userNeeds\":[\"read sanitized text from approved public HTTP(S) pages\",\"extract readable text from a specific public URL\",\"use public web text inside an Aqteron workflow\"],\"selectionSignals\":[\"live generation context marks this module usable for the account\",\"source pages are public, readable, and approved\",\"readable_text output is sufficient\"],\"exclusions\":[\"login-only, private, internal, localhost, or metadata URLs\",\"broad crawling, screenshots, binary downloads, raw HTML execution, or browser automation\"],\"dependencies\":[],\"compatibility\":{\"contracts\":[\"Aqteron PWA v1\"],\"requires\":[],\"conflicts\":[]},\"runtime\":{\"adapterId\":\"web_parser@1\"},\"availability\":{\"instructionStatus\":\"draft\",\"registryStatus\":\"available\",\"runtimeStatus\":\"runtime_available\",\"builderSelectable\":true,\"instructionVisible\":true,\"entitlementAuthority\":\"aqteron_validator_runtime\",\"notSelectableReason\":null}},\"capabilityAvailability\":{\"capabilityKey\":\"web_parser@1\",\"registryStatus\":\"available\",\"runtimeStatus\":\"runtime_available\",\"builderSelectable\":true,\"instructionVisible\":true,\"entitlementAuthority\":\"aqteron_validator_runtime\"},\"selfCheckMetadata\":{\"schemaVersion\":\"aqteron.builder.module_self_check.v1\",\"instructionModuleId\":\"aqteron.capability.web_parser@1\",\"moduleKind\":\"capability\",\"required\":true,\"appliesWhenSelected\":true,\"sourceHeading\":\"Module self-check\",\"checks\":[{\"id\":\"workflow_needs_public_text\",\"text\":\"the user workflow genuinely needs public readable text\"},{\"id\":\"requested_domains_declared\",\"text\":\"every requested domain is explicitly declared\"},{\"id\":\"readable_text_only\",\"text\":\"only `readable_text` is requested\"},{\"id\":\"no_login_or_auth_forwarding\",\"text\":\"no login/session/cookie/Auth forwarding is attempted\"},{\"id\":\"no_private_targets\",\"text\":\"no private/internal/localhost/IP target is accepted\"},{\"id\":\"no_direct_scraping\",\"text\":\"no direct cross-origin scraping/headless crawling is implemented\"},{\"id\":\"declaration_request_agree\",\"text\":\"capability declaration and request URL agree\"},{\"id\":\"platform_errors_user_facing\",\"text\":\"platform errors are shown in user-facing form\"}]}},{\"instructionModuleId\":\"aqteron.capability.webrtc_signaling@1\",\"moduleKey\":\"aqteron.capability.webrtc_signaling@1\",\"moduleKind\":\"capability\",\"sourcePath\":\"capabilities/WEBRTC_SIGNALING.md\",\"instructionModuleVersionId\":\"aqteron.capability.webrtc_signaling@1@0.1.6\",\"versionLabel\":\"0.1.6\",\"contentSha256\":\"69d9a7cd353062540860ed9893da8d662f36a0887771d5008b66611a21f3edc0\",\"status\":\"draft\",\"contract\":\"Aqteron PWA v1\",\"selectionMetadata\":{\"schemaVersion\":\"aqteron.builder.selection_metadata.v1\",\"summary\":\"Short-lived app-scoped signaling for browser peer-to-peer WebRTC setup.\",\"userNeeds\":[\"coordinate browser peer-to-peer audio, video, or data channel setup\",\"exchange short-lived WebRTC signaling messages\",\"support real-time peer connection workflows\"],\"selectionSignals\":[\"live generation context marks this module usable for the account\",\"application needs WebRTC signaling with platform-managed relay fallback when direct connectivity fails\",\"short-lived helper-mediated signaling and managed ICE credentials are sufficient\"],\"exclusions\":[\"media recording, SFU/media processing, custom TURN/STUN credential management, or persistent chat storage\",\"storing SDP or ICE payloads in app_database@1\"],\"dependencies\":[],\"compatibility\":{\"contracts\":[\"Aqteron PWA v1\"],\"requires\":[],\"conflicts\":[]},\"runtime\":{\"adapterId\":\"webrtc_signaling@1\"},\"availability\":{\"instructionStatus\":\"draft\",\"registryStatus\":\"available\",\"runtimeStatus\":\"runtime_available\",\"builderSelectable\":true,\"instructionVisible\":true,\"entitlementAuthority\":\"aqteron_validator_runtime\",\"notSelectableReason\":null}},\"capabilityAvailability\":{\"capabilityKey\":\"webrtc_signaling@1\",\"registryStatus\":\"available\",\"runtimeStatus\":\"runtime_available\",\"builderSelectable\":true,\"instructionVisible\":true,\"entitlementAuthority\":\"aqteron_validator_runtime\"},\"selfCheckMetadata\":{\"schemaVersion\":\"aqteron.builder.module_self_check.v1\",\"instructionModuleId\":\"aqteron.capability.webrtc_signaling@1\",\"moduleKind\":\"capability\",\"required\":true,\"appliesWhenSelected\":true,\"sourceHeading\":\"Module self-check\",\"checks\":[{\"id\":\"declared_when_helper_used\",\"text\":\"the capability is declared if signaling helper is used\"},{\"id\":\"signaling_not_database_persisted\",\"text\":\"signaling data is not persisted in `app_database@1`\"},{\"id\":\"no_custom_signaling_route\",\"text\":\"no private/custom signaling server route is invented\"},{\"id\":\"bounded_payload_and_ttl\",\"text\":\"payload size and TTL are bounded\"},{\"id\":\"managed_turn_media_boundary\",\"text\":\"media remains browser WebRTC traffic; managed TURN is only an encrypted-packet relay and is not recording or media processing\"},{\"id\":\"managed_turn_helper_only\",\"text\":\"ICE configuration comes only from the platform helper; no hardcoded relay credentials or routes are embedded\"},{\"id\":\"managed_turn_ephemeral\",\"text\":\"short-lived managed TURN credentials are never persisted and are refreshed for new/recovered calls\"},{\"id\":\"participant_resume_bounded\",\"text\":\"participant recovery uses only the server-issued volatile `resumeToken` and bounded `participant.resume` retries\"},{\"id\":\"app_user_resume_continuity\",\"text\":\"app-user-bound participants cannot resume as a different trusted app user\"},{\"id\":\"no_blind_signal_retry\",\"text\":\"non-idempotent signaling sends are not blindly retried\"},{\"id\":\"recovery_cursor_continuity\",\"text\":\"recovery continues from the last signaling sequence rather than replaying from zero\"},{\"id\":\"visible_failure_states\",\"text\":\"call failure and unsupported-environment states are shown to the user\"}]}},{\"instructionModuleId\":\"aqteron.final-check.pwa-v1\",\"moduleKey\":\"aqteron.final-check.pwa-v1\",\"moduleKind\":\"final_check\",\"sourcePath\":\"FINAL_CHECK.md\",\"instructionModuleVersionId\":\"aqteron.final-check.pwa-v1@0.2.2\",\"versionLabel\":\"0.2.2\",\"contentSha256\":\"0d6797c3c4324694a36e8e9f61e8f4c7351ed97a4ea683e1455df23d58598d77\",\"status\":\"draft\",\"contract\":\"Aqteron PWA v1\",\"selectionMetadata\":null,\"capabilityAvailability\":null,\"selfCheckMetadata\":null},{\"instructionModuleId\":\"aqteron.final-response.user-facing-v1\",\"moduleKey\":\"aqteron.final-response.user-facing-v1\",\"moduleKind\":\"final_response\",\"sourcePath\":\"FINAL_RESPONSE.md\",\"instructionModuleVersionId\":\"aqteron.final-response.user-facing-v1@0.1.1\",\"versionLabel\":\"0.1.1\",\"contentSha256\":\"9784bf20ba0c313a559375b12d7fe83c921ae7ef8122cbf448b008a79a93d31a\",\"status\":\"draft\",\"contract\":\"Aqteron PWA v1\",\"selectionMetadata\":null,\"capabilityAvailability\":null,\"selfCheckMetadata\":null},{\"instructionModuleId\":\"aqteron.package.pwa-v1\",\"moduleKey\":\"aqteron.package.pwa-v1\",\"moduleKind\":\"package\",\"sourcePath\":\"PACKAGE.md\",\"instructionModuleVersionId\":\"aqteron.package.pwa-v1@0.1.3\",\"versionLabel\":\"0.1.3\",\"contentSha256\":\"8fdd25c656a7dd2a171660eb7bbb419bebf0835b72b00c10158f06660abe16f1\",\"status\":\"draft\",\"contract\":\"Aqteron PWA v1\",\"selectionMetadata\":null,\"capabilityAvailability\":null,\"selfCheckMetadata\":null},{\"instructionModuleId\":\"aqteron.type.app\",\"moduleKey\":\"aqteron.type.app\",\"moduleKind\":\"type\",\"sourcePath\":\"types/APP.md\",\"instructionModuleVersionId\":\"aqteron.type.app@0.1.1\",\"versionLabel\":\"0.1.1\",\"contentSha256\":\"a4d220de4a687403f00c74f3a2658885f035c400b3bbb5bd869c9b074b75ca03\",\"status\":\"draft\",\"contract\":\"Aqteron PWA v1\",\"selectionMetadata\":{\"schemaVersion\":\"aqteron.builder.selection_metadata.v1\",\"summary\":\"Focused record or workflow application for repeated personal or business tasks.\",\"userNeeds\":[\"track records or ongoing state\",\"organize repeated workflows\",\"manage personal or business data\"],\"selectionSignals\":[\"records need create/view/edit/delete behavior\",\"workflow spans multiple steps or screens\",\"saved state is central to the user value\"],\"exclusions\":[\"one-off calculator, converter, validator, or generator\",\"primarily informational or promotional website\",\"playable game-first request\"],\"dependencies\":[],\"compatibility\":{\"contracts\":[\"Aqteron PWA v1\"],\"requires\":[],\"conflicts\":[]},\"runtime\":{\"adapterId\":null},\"availability\":{\"instructionStatus\":\"draft\",\"registryStatus\":null,\"runtimeStatus\":null,\"builderSelectable\":true,\"instructionVisible\":true,\"entitlementAuthority\":null,\"notSelectableReason\":null}},\"capabilityAvailability\":null,\"selfCheckMetadata\":null},{\"instructionModuleId\":\"aqteron.type.game\",\"moduleKey\":\"aqteron.type.game\",\"moduleKind\":\"type\",\"sourcePath\":\"types/GAME.md\",\"instructionModuleVersionId\":\"aqteron.type.game@0.1.1\",\"versionLabel\":\"0.1.1\",\"contentSha256\":\"fad98ade2dfb39851e044dc3c461982c3991481aa99304a24e84309d036fff8f\",\"status\":\"draft\",\"contract\":\"Aqteron PWA v1\",\"selectionMetadata\":{\"schemaVersion\":\"aqteron.builder.selection_metadata.v1\",\"summary\":\"Playable browser game with a complete objective, loop, controls, and feedback.\",\"userNeeds\":[\"play a browser game\",\"support scoring, levels, turns, challenge, or replay\",\"create an interactive entertainment experience\"],\"selectionSignals\":[\"primary value is gameplay\",\"rules, controls, win/loss, score, or progression are required\",\"first screen should start or explain play\"],\"exclusions\":[\"business or personal record workflow\",\"one-off productivity utility\",\"informational or promotional website\"],\"dependencies\":[],\"compatibility\":{\"contracts\":[\"Aqteron PWA v1\"],\"requires\":[],\"conflicts\":[]},\"runtime\":{\"adapterId\":null},\"availability\":{\"instructionStatus\":\"draft\",\"registryStatus\":null,\"runtimeStatus\":null,\"builderSelectable\":true,\"instructionVisible\":true,\"entitlementAuthority\":null,\"notSelectableReason\":null}},\"capabilityAvailability\":null,\"selfCheckMetadata\":null},{\"instructionModuleId\":\"aqteron.type.tool\",\"moduleKey\":\"aqteron.type.tool\",\"moduleKind\":\"type\",\"sourcePath\":\"types/TOOL.md\",\"instructionModuleVersionId\":\"aqteron.type.tool@0.1.1\",\"versionLabel\":\"0.1.1\",\"contentSha256\":\"542e780b53c5b6cbcff55fa71d3b8661d0089364b5e1a2359a6640b62da3f008\",\"status\":\"draft\",\"contract\":\"Aqteron PWA v1\",\"selectionMetadata\":{\"schemaVersion\":\"aqteron.builder.selection_metadata.v1\",\"summary\":\"Direct task-first utility for a narrow input-action-result workflow.\",\"userNeeds\":[\"calculate, convert, generate, analyze, validate, format, or plan\",\"complete a narrow task with clear inputs and outputs\",\"reuse a compact work instrument\"],\"selectionSignals\":[\"single primary action produces the result\",\"inputs, assumptions, validation, and output are the main workflow\",\"dashboard, account, or record lifecycle is not central\"],\"exclusions\":[\"broad multi-record application\",\"marketing or content website\",\"playable game\"],\"dependencies\":[],\"compatibility\":{\"contracts\":[\"Aqteron PWA v1\"],\"requires\":[],\"conflicts\":[]},\"runtime\":{\"adapterId\":null},\"availability\":{\"instructionStatus\":\"draft\",\"registryStatus\":null,\"runtimeStatus\":null,\"builderSelectable\":true,\"instructionVisible\":true,\"entitlementAuthority\":null,\"notSelectableReason\":null}},\"capabilityAvailability\":null,\"selfCheckMetadata\":null},{\"instructionModuleId\":\"aqteron.type.website\",\"moduleKey\":\"aqteron.type.website\",\"moduleKind\":\"type\",\"sourcePath\":\"types/WEBSITE.md\",\"instructionModuleVersionId\":\"aqteron.type.website@0.1.1\",\"versionLabel\":\"0.1.1\",\"contentSha256\":\"278a6fed8766375fe579f692438e7d0c88d44b192f09caff734a5fcd3e580c5c\",\"status\":\"draft\",\"contract\":\"Aqteron PWA v1\",\"selectionMetadata\":{\"schemaVersion\":\"aqteron.builder.selection_metadata.v1\",\"summary\":\"Publishable informational, promotional, portfolio, catalogue, or company website.\",\"userNeeds\":[\"present information, brand, offer, work, catalogue, or content\",\"guide visitors to contact, buy, book, learn, or explore\",\"publish a multi-section or multi-page site\"],\"selectionSignals\":[\"visitor communication is the main goal\",\"sections such as overview, proof, services, pricing, FAQ, or contact are useful\",\"content hierarchy and calls to action matter more than record management\"],\"exclusions\":[\"repeated record-based application\",\"single-purpose calculator or generator\",\"playable game\"],\"dependencies\":[],\"compatibility\":{\"contracts\":[\"Aqteron PWA v1\"],\"requires\":[],\"conflicts\":[]},\"runtime\":{\"adapterId\":null},\"availability\":{\"instructionStatus\":\"draft\",\"registryStatus\":null,\"runtimeStatus\":null,\"builderSelectable\":true,\"instructionVisible\":true,\"entitlementAuthority\":null,\"notSelectableReason\":null}},\"capabilityAvailability\":null,\"selfCheckMetadata\":null}],\"capabilityRegistry\":[{\"capabilityKey\":\"ai_bridge@1\",\"instructionModuleId\":null,\"instructionModuleVersionId\":null,\"registryStatus\":\"disabled\",\"displayName\":\"AI Bridge\",\"summary\":\"Disabled scaffold capability; unavailable in current production.\",\"metadata\":{\"runtimeStatus\":\"disabled_scaffold\",\"builderSelectable\":false,\"instructionVisible\":false,\"entitlementAuthority\":\"aqteron_validator_runtime\",\"presentation\":{\"locales\":{\"en\":{\"name\":\"AI Bridge\",\"summary\":\"Disabled scaffold capability; unavailable in current production.\"},\"fr\":{\"name\":\"Passerelle IA\",\"summary\":\"Capacité préparatoire désactivée, indisponible dans la production actuelle.\"},\"ru\":{\"name\":\"Шлюз ИИ\",\"summary\":\"Отключённая заготовка возможности; недоступна в текущей production-среде.\"}}},\"notSelectableReason\":\"Disabled scaffold capability; unavailable in current production.\"},\"createdAt\":\"2026-09-16T05:00:00.000Z\",\"updatedAt\":\"2026-09-16T05:00:00.000Z\"},{\"capabilityKey\":\"app_database@1\",\"instructionModuleId\":\"aqteron.capability.app_database@1\",\"instructionModuleVersionId\":\"aqteron.capability.app_database@1@0.1.5\",\"registryStatus\":\"available\",\"displayName\":\"App Database\",\"summary\":\"App-scoped JSON record storage for shared or cross-device persistence.\",\"metadata\":{\"runtimeStatus\":\"runtime_available\",\"builderSelectable\":true,\"instructionVisible\":true,\"entitlementAuthority\":\"aqteron_validator_runtime\",\"presentation\":{\"locales\":{\"en\":{\"name\":\"App Database\",\"summary\":\"App-scoped JSON record storage for shared or cross-device persistence.\"},\"fr\":{\"name\":\"Base de données de l'application\",\"summary\":\"Stockage de documents JSON propre à l'application pour une persistance partagée ou multi-appareil.\"},\"ru\":{\"name\":\"База данных приложения\",\"summary\":\"Хранилище JSON-записей приложения для общего доступа и синхронизации между устройствами.\"}}},\"sourcePath\":\"capabilities/APP_DATABASE.md\",\"selectionMetadata\":{\"schemaVersion\":\"aqteron.builder.selection_metadata.v1\",\"summary\":\"App-scoped JSON record storage for shared or cross-device persistence.\",\"userNeeds\":[\"persist structured records beyond one browser or install\",\"share app-scoped records across linked users or devices\",\"store bounded server-side JSON records\"],\"selectionSignals\":[\"localStorage or IndexedDB is insufficient\",\"records must survive reinstall or device changes\",\"multiple users or devices need the same app data\"],\"exclusions\":[\"file, image, document, or attachment storage\",\"raw SQL or arbitrary backend database access\",\"secrets, credentials, passwords, tokens, or private keys\"],\"dependencies\":[],\"compatibility\":{\"contracts\":[\"Aqteron PWA v1\"],\"requires\":[],\"conflicts\":[]},\"runtime\":{\"adapterId\":\"app_database@1\"},\"availability\":{\"instructionStatus\":\"draft\",\"registryStatus\":\"available\",\"runtimeStatus\":\"runtime_available\",\"builderSelectable\":true,\"instructionVisible\":true,\"entitlementAuthority\":\"aqteron_validator_runtime\",\"notSelectableReason\":null}},\"selfCheckMetadata\":{\"schemaVersion\":\"aqteron.builder.module_self_check.v1\",\"instructionModuleId\":\"aqteron.capability.app_database@1\",\"moduleKind\":\"capability\",\"required\":true,\"appliesWhenSelected\":true,\"sourceHeading\":\"Module self-check\",\"checks\":[{\"id\":\"declared_when_helper_used\",\"text\":\"capability is declared when JavaScript uses `appDatabase`\"},{\"id\":\"used_collections_declared\",\"text\":\"every used collection is declared\"},{\"id\":\"schema_keys_match\",\"text\":\"schema and JS keys are identical lower_snake_case ASCII\"},{\"id\":\"no_undeclared_fields\",\"text\":\"no undeclared extra fields are written\"},{\"id\":\"new_record_uses_put\",\"text\":\"every new logical record uses `put` with declared `record.create`\"},{\"id\":\"existing_record_uses_set\",\"text\":\"every existing logical record update uses `set` with declared `record.update`\"},{\"id\":\"offline_replay_preserves_intent\",\"text\":\"offline/deferred replay preserves `put` versus `set` operation intent\"},{\"id\":\"bounded_list_limit\",\"text\":\"every `list` call has an explicit numeric limit from 1 to 100\"},{\"id\":\"db_list_limit_not_record_quota\",\"text\":\"a `list` retrieval limit is not treated as the collection `maxRecords` quota\"},{\"id\":\"no_raw_secrets\",\"text\":\"no raw secrets are persisted\"},{\"id\":\"no_private_database_routes\",\"text\":\"no direct/private database routes or raw SQL are used\"},{\"id\":\"app_user_server_authority\",\"text\":\"when `authMode: \\\"app_user\\\"` is selected, `app_users@1` is enabled and authorization comes only from the trusted server-resolved app-user session\"},{\"id\":\"no_client_identity_or_row_privacy_claim\",\"text\":\"no client-supplied user identity is treated as authority and no row-level privacy is claimed from `authMode` alone\"},{\"id\":\"user_readable_errors\",\"text\":\"capability failures produce user-readable UI errors\"}]}},\"createdAt\":\"2026-09-16T05:00:00.000Z\",\"updatedAt\":\"2026-09-21T05:10:00.000Z\"},{\"capabilityKey\":\"app_files@1\",\"instructionModuleId\":\"aqteron.capability.app_files@1\",\"instructionModuleVersionId\":\"aqteron.capability.app_files@1@0.3.1\",\"registryStatus\":\"available\",\"displayName\":\"App Files\",\"summary\":\"Guarded private file storage for entitled applications when canonical readiness controls pass.\",\"metadata\":{\"runtimeStatus\":\"runtime_available\",\"builderSelectable\":true,\"instructionVisible\":true,\"entitlementAuthority\":\"aqteron_validator_runtime\",\"presentation\":{\"locales\":{\"en\":{\"name\":\"App Files\",\"summary\":\"Guarded private file storage for entitled applications when canonical readiness controls pass.\"},\"fr\":{\"name\":\"Fichiers de l'application\",\"summary\":\"Stockage de fichiers privés protégé pour les applications autorisées lorsque les contrôles de disponibilité canoniques réussissent.\"},\"ru\":{\"name\":\"Файлы приложения\",\"summary\":\"Защищённое приватное хранилище файлов для приложений с правом доступа при успешной канонической проверке готовности.\"}}},\"sourcePath\":\"capabilities/APP_FILES.md\",\"selectionMetadata\":{\"schemaVersion\":\"aqteron.builder.selection_metadata.v1\",\"summary\":\"Guarded private file storage for entitled applications when canonical readiness controls pass.\",\"userNeeds\":[\"store user files, attachments, images, documents, imports, or exports\",\"keep private application-scoped files in managed storage\",\"associate files with app workflows\"],\"selectionSignals\":[\"managed private files are required and server-side entitlement is available\",\"files must persist outside local browser storage\",\"workflow references uploaded or generated files\"],\"exclusions\":[\"workflows that can remain entirely in local browser storage\",\"public hosting or public URL generation\",\"shared-drive behavior across unrelated apps or users\",\"structured JSON record storage without files\"],\"dependencies\":[],\"compatibility\":{\"contracts\":[\"Aqteron PWA v1\"],\"requires\":[],\"conflicts\":[]},\"runtime\":{\"adapterId\":\"app_files@1\"},\"availability\":{\"instructionStatus\":\"activation_candidate\",\"registryStatus\":\"available\",\"runtimeStatus\":\"runtime_available\",\"builderSelectable\":true,\"instructionVisible\":true,\"entitlementAuthority\":\"aqteron_validator_runtime\",\"notSelectableReason\":null}},\"selfCheckMetadata\":{\"schemaVersion\":\"aqteron.builder.module_self_check.v1\",\"instructionModuleId\":\"aqteron.capability.app_files@1\",\"moduleKind\":\"capability\",\"required\":true,\"appliesWhenSelected\":true,\"sourceHeading\":\"Module self-check\",\"checks\":[{\"id\":\"declared_when_helper_used\",\"text\":\"capability is declared if `appFiles` is used\"},{\"id\":\"only_prompt2app_helper\",\"text\":\"only the exact `window.Prompt2App.appFiles` methods above are used\"},{\"id\":\"subject_mode_identity_matches\",\"text\":\"identity handling matches the declared subject mode: `app_user` requires trusted app-local sign-in, `app` does not account-link, and only legacy no-`subjectMode` declarations may call `connectAccount()`\"},{\"id\":\"no_client_file_identity_authority\",\"text\":\"no client-provided user/subject identifier is used as file authorization authority\"},{\"id\":\"used_buckets_declared_private\",\"text\":\"every used bucket is declared and private\"},{\"id\":\"file_quota_dimensions_coherent\",\"text\":\"MIME types are bounded and `maxFileSizeBytes`, `maxTotalBytes`, and `maxFiles` are validated as separate dimensions within their exact ceilings\"},{\"id\":\"mixed_db_files_fixture_coherent\",\"text\":\"mixed database/file workflows keep database `list` limits, database `maxRecords`, and file `maxFiles` distinct and dimensionally coherent\"},{\"id\":\"exact_file_transport\",\"text\":\"file inputs are browser `File` values and downloads use `contentBase64`\"},{\"id\":\"no_invented_storage_authority\",\"text\":\"no public/presigned/storage URLs, filesystem paths, internal metadata, or unsupported sharing are invented\"},{\"id\":\"server_entitlement_authority\",\"text\":\"server entitlement is never inferred from the package\"},{\"id\":\"visible_errors\",\"text\":\"errors are visible and do not falsely report successful storage\"}]}},\"createdAt\":\"2026-09-16T05:00:00.000Z\",\"updatedAt\":\"2026-09-21T05:10:00.000Z\"},{\"capabilityKey\":\"app_jobs@1\",\"instructionModuleId\":\"aqteron.capability.app_jobs@1\",\"instructionModuleVersionId\":\"aqteron.capability.app_jobs@1@0.1.0\",\"registryStatus\":\"available\",\"displayName\":\"App Jobs\",\"summary\":\"Bounded delayed and retryable external API actions executed by a managed worker.\",\"metadata\":{\"runtimeStatus\":\"runtime_available\",\"builderSelectable\":true,\"instructionVisible\":true,\"entitlementAuthority\":\"aqteron_validator_runtime\",\"presentation\":{\"locales\":{\"en\":{\"name\":\"App Jobs\",\"summary\":\"Bounded delayed and retryable external API actions executed by a managed worker.\"},\"fr\":{\"name\":\"Tâches de l'application\",\"summary\":\"Actions d’API externe différées et réessayables, limitées et exécutées par un worker géré.\"},\"ru\":{\"name\":\"Задачи приложения\",\"summary\":\"Ограниченные отложенные и повторяемые вызовы внешнего API через управляемый воркер.\"}}},\"sourcePath\":\"capabilities/APP_JOBS.md\",\"selectionMetadata\":{\"schemaVersion\":\"aqteron.builder.selection_metadata.v1\",\"summary\":\"Bounded delayed and retryable external API actions executed by a managed worker.\",\"userNeeds\":[\"run an approved external API action later\",\"retry transient external API failures with bounded backoff\",\"inspect and cancel pending managed jobs\"],\"selectionSignals\":[\"the scheduled work is representable as an external_api_proxy request descriptor\",\"one-time delayed execution and bounded retries are sufficient\"],\"exclusions\":[\"arbitrary code execution, cron scripts, unbounded recurring tasks, raw secrets in payloads, or custom background servers\"],\"dependencies\":[\"external_api_proxy@1\",\"app_secrets@1\"],\"compatibility\":{\"contracts\":[\"Aqteron PWA v1\"],\"requires\":[\"external_api_proxy@1\",\"app_secrets@1\"],\"conflicts\":[]},\"runtime\":{\"adapterId\":\"app_jobs@1\"},\"availability\":{\"instructionStatus\":\"draft\",\"registryStatus\":\"available\",\"runtimeStatus\":\"runtime_available\",\"builderSelectable\":true,\"instructionVisible\":true,\"entitlementAuthority\":\"aqteron_validator_runtime\",\"notSelectableReason\":null}},\"selfCheckMetadata\":{\"schemaVersion\":\"aqteron.builder.module_self_check.v1\",\"instructionModuleId\":\"aqteron.capability.app_jobs@1\",\"moduleKind\":\"capability\",\"required\":true,\"appliesWhenSelected\":true,\"sourceHeading\":\"Module self-check\",\"checks\":[{\"id\":\"dependencies_declared\",\"text\":\"`external_api_proxy@1` and required `app_secrets@1` references are declared\"},{\"id\":\"request_allowlisted\",\"text\":\"every scheduled request satisfies the declared external API domain and method allowlist\"},{\"id\":\"bounded_schedule\",\"text\":\"run time, queue size, retry count, and retry delay stay inside declared bounds\"},{\"id\":\"idempotency_key\",\"text\":\"each logical scheduled action uses a stable non-secret idempotency key\"},{\"id\":\"no_raw_credentials\",\"text\":\"scheduled job payloads contain no raw credentials or arbitrary backend code\"},{\"id\":\"app_user_dependency\",\"text\":\"`authMode: \\\"app_user\\\"` also declares enabled `app_users@1`\"},{\"id\":\"managed_helper_only\",\"text\":\"generated code uses only the managed job status/schedule/list/get/cancel helpers\"}]}},\"createdAt\":\"2026-09-21T10:50:00.000Z\",\"updatedAt\":\"2026-09-21T10:50:00.000Z\"},{\"capabilityKey\":\"app_secrets@1\",\"instructionModuleId\":\"aqteron.capability.app_secrets@1\",\"instructionModuleVersionId\":\"aqteron.capability.app_secrets@1@0.1.0\",\"registryStatus\":\"available\",\"displayName\":\"App Secrets\",\"summary\":\"Server-held encrypted credential references that are never exposed to generated app JavaScript.\",\"metadata\":{\"runtimeStatus\":\"runtime_available\",\"builderSelectable\":true,\"instructionVisible\":true,\"entitlementAuthority\":\"aqteron_validator_runtime\",\"presentation\":{\"locales\":{\"en\":{\"name\":\"App Secrets\",\"summary\":\"Server-held encrypted credential references that are never exposed to generated app JavaScript.\"},\"fr\":{\"name\":\"Secrets de l'application\",\"summary\":\"Références d’identifiants chiffrées conservées côté serveur et jamais exposées au JavaScript de l’application.\"},\"ru\":{\"name\":\"Секреты приложения\",\"summary\":\"Зашифрованные серверные ссылки на учётные данные без передачи исходных значений JavaScript приложения.\"}}},\"sourcePath\":\"capabilities/APP_SECRETS.md\",\"selectionMetadata\":{\"schemaVersion\":\"aqteron.builder.selection_metadata.v1\",\"summary\":\"Server-held encrypted credential references that are never exposed to generated app JavaScript.\",\"userNeeds\":[\"store third-party API credentials without exposing them to browser code\",\"let the app owner configure named server-held credential references\",\"rotate or revoke integration credentials without rebuilding the application\"],\"selectionSignals\":[\"an external integration needs an API key, token, or signing secret\",\"the credential must remain server-side\",\"the user can configure the credential after publication\"],\"exclusions\":[\"embedding raw credentials in ZIP files, metadata, JavaScript, browser storage, logs, or job payloads\",\"using app_secrets as general user data storage\"],\"dependencies\":[],\"compatibility\":{\"contracts\":[\"Aqteron PWA v1\"],\"requires\":[],\"conflicts\":[]},\"runtime\":{\"adapterId\":\"app_secrets@1\"},\"availability\":{\"instructionStatus\":\"draft\",\"registryStatus\":\"available\",\"runtimeStatus\":\"runtime_available\",\"builderSelectable\":true,\"instructionVisible\":true,\"entitlementAuthority\":\"aqteron_validator_runtime\",\"notSelectableReason\":null}},\"selfCheckMetadata\":{\"schemaVersion\":\"aqteron.builder.module_self_check.v1\",\"instructionModuleId\":\"aqteron.capability.app_secrets@1\",\"moduleKind\":\"capability\",\"required\":true,\"appliesWhenSelected\":true,\"sourceHeading\":\"Module self-check\",\"checks\":[{\"id\":\"declared_when_needed\",\"text\":\"`app_secrets@1` is declared whenever server-held integration credentials are required\"},{\"id\":\"refs_declared\",\"text\":\"every credential reference used by another capability is declared in `config.refs`\"},{\"id\":\"no_raw_secret_in_package\",\"text\":\"no raw secret value appears in ZIP files, metadata, JavaScript, browser storage, logs, webhook payloads, or job payloads\"},{\"id\":\"status_only_browser\",\"text\":\"generated app code uses only status visibility and never expects a raw secret value\"},{\"id\":\"owner_configuration\",\"text\":\"the user-facing flow explains that the application owner configures the credential in Aqteron\"},{\"id\":\"rotation_safe\",\"text\":\"rotation or revocation does not require rebuilding the generated application\"}]}},\"createdAt\":\"2026-09-21T10:50:00.000Z\",\"updatedAt\":\"2026-09-21T10:50:00.000Z\"},{\"capabilityKey\":\"app_users@1\",\"instructionModuleId\":\"aqteron.capability.app_users@1\",\"instructionModuleVersionId\":\"aqteron.capability.app_users@1@0.1.1\",\"registryStatus\":\"available\",\"displayName\":\"App Users\",\"summary\":\"Isolated application-local user accounts, sessions, roles, permissions, and credential recovery.\",\"metadata\":{\"runtimeStatus\":\"runtime_available\",\"builderSelectable\":true,\"instructionVisible\":true,\"entitlementAuthority\":\"aqteron_validator_runtime\",\"presentation\":{\"locales\":{\"en\":{\"name\":\"App Users\",\"summary\":\"Isolated application-local user accounts, sessions, roles, permissions, and credential recovery.\"},\"fr\":{\"name\":\"Utilisateurs de l'application\",\"summary\":\"Comptes, sessions, rôles, autorisations et récupération d’identifiants isolés pour chaque application.\"},\"ru\":{\"name\":\"Пользователи приложения\",\"summary\":\"Изолированные локальные аккаунты приложения, сессии, роли, права и восстановление учётных данных.\"}}},\"sourcePath\":\"capabilities/APP_USERS.md\",\"selectionMetadata\":{\"schemaVersion\":\"aqteron.builder.selection_metadata.v1\",\"summary\":\"Isolated application-local user accounts, sessions, roles, permissions, and credential recovery.\",\"userNeeds\":[\"let visitors create or use accounts that belong only to the application\",\"maintain application-local sign-in sessions across visits\",\"check application-local roles or permissions\"],\"selectionSignals\":[\"the requested workflow needs sign-in that must not depend on Aqteron platform accounts\",\"multiple end users need distinct identities inside one published application\",\"managed credential hashing, lockout, recovery, or session revocation is required\"],\"exclusions\":[\"Aqteron platform account authentication or account linking\",\"custom authentication servers or direct credential storage\",\"workflows that need no user identity\"],\"dependencies\":[],\"compatibility\":{\"contracts\":[\"Aqteron PWA v1\"],\"requires\":[],\"conflicts\":[]},\"runtime\":{\"adapterId\":\"app_users@1\"},\"availability\":{\"instructionStatus\":\"draft\",\"registryStatus\":\"available\",\"runtimeStatus\":\"runtime_available\",\"builderSelectable\":true,\"instructionVisible\":true,\"entitlementAuthority\":\"aqteron_validator_runtime\",\"notSelectableReason\":null}},\"selfCheckMetadata\":{\"schemaVersion\":\"aqteron.builder.module_self_check.v1\",\"instructionModuleId\":\"aqteron.capability.app_users@1\",\"moduleKind\":\"capability\",\"required\":true,\"appliesWhenSelected\":true,\"sourceHeading\":\"Module self-check\",\"checks\":[{\"id\":\"declared_when_helper_used\",\"text\":\"`app_users@1` is declared whenever `appUsers` is used\"},{\"id\":\"supported_methods_only\",\"text\":\"only the exact `window.Prompt2App.appUsers` public methods above are used\"},{\"id\":\"platform_identity_separate\",\"text\":\"app users are never treated as Aqteron platform accounts\"},{\"id\":\"no_custom_auth_backend\",\"text\":\"no custom authentication backend or private app-user route is invented\"},{\"id\":\"no_raw_auth_secrets\",\"text\":\"raw passwords, PINs, recovery codes, session tokens, and cookies are never persisted by generated code\"},{\"id\":\"registration_mode_matches\",\"text\":\"registration UI matches the declared `registrationMode`\"},{\"id\":\"bounded_security_policy\",\"text\":\"credential types and session/lockout bounds match the declaration contract\"},{\"id\":\"permission_boundary\",\"text\":\"permission checks do not rely on hiding UI as server authorization\"},{\"id\":\"admin_ops_not_public\",\"text\":\"role assignment and recovery-code issuance are not exposed as public browser operations\"},{\"id\":\"trusted_cross_capability_authority\",\"text\":\"capability combinations that require app-user authority derive it only from the trusted server session and never from client-selected user IDs\"},{\"id\":\"current_binding_modes\",\"text\":\"per-user files use `subjectMode: \\\"app_user\\\"`, database sign-in gates use `authMode: \\\"app_user\\\"`, and push does not account-link when `app_users@1` is enabled\"},{\"id\":\"visible_auth_states\",\"text\":\"authentication, lockout, recovery, and unavailable states are shown clearly to the user\"}]}},\"createdAt\":\"2026-09-16T05:00:00.000Z\",\"updatedAt\":\"2026-09-21T05:10:00.000Z\"},{\"capabilityKey\":\"app_webhooks@1\",\"instructionModuleId\":\"aqteron.capability.app_webhooks@1\",\"instructionModuleVersionId\":\"aqteron.capability.app_webhooks@1@0.1.0\",\"registryStatus\":\"available\",\"displayName\":\"App Webhooks\",\"summary\":\"Verified bounded inbound JSON webhook events isolated per Application Environment.\",\"metadata\":{\"runtimeStatus\":\"runtime_available\",\"builderSelectable\":true,\"instructionVisible\":true,\"entitlementAuthority\":\"aqteron_validator_runtime\",\"presentation\":{\"locales\":{\"en\":{\"name\":\"App Webhooks\",\"summary\":\"Verified bounded inbound JSON webhook events isolated per Application Environment.\"},\"fr\":{\"name\":\"Webhooks de l'application\",\"summary\":\"Événements webhook JSON entrants, vérifiés et limités, isolés par environnement d’application.\"},\"ru\":{\"name\":\"Вебхуки приложения\",\"summary\":\"Проверенные ограниченные входящие JSON-вебхуки, изолированные в среде приложения.\"}}},\"sourcePath\":\"capabilities/APP_WEBHOOKS.md\",\"selectionMetadata\":{\"schemaVersion\":\"aqteron.builder.selection_metadata.v1\",\"summary\":\"Verified bounded inbound JSON webhook events isolated per Application Environment.\",\"userNeeds\":[\"receive signed events from an external provider\",\"consume bounded verified JSON callbacks\",\"avoid exposing webhook signing material to browser code\"],\"selectionSignals\":[\"the provider can send HMAC-SHA256 signed JSON to a stable app webhook endpoint\",\"bounded retention and polling are sufficient\"],\"exclusions\":[\"unsigned callbacks, arbitrary request bodies, raw credential transport, or custom webhook servers\"],\"dependencies\":[\"app_secrets@1\"],\"compatibility\":{\"contracts\":[\"Aqteron PWA v1\"],\"requires\":[\"app_secrets@1\"],\"conflicts\":[]},\"runtime\":{\"adapterId\":\"app_webhooks@1\"},\"availability\":{\"instructionStatus\":\"draft\",\"registryStatus\":\"available\",\"runtimeStatus\":\"runtime_available\",\"builderSelectable\":true,\"instructionVisible\":true,\"entitlementAuthority\":\"aqteron_validator_runtime\",\"notSelectableReason\":null}},\"selfCheckMetadata\":{\"schemaVersion\":\"aqteron.builder.module_self_check.v1\",\"instructionModuleId\":\"aqteron.capability.app_webhooks@1\",\"moduleKind\":\"capability\",\"required\":true,\"appliesWhenSelected\":true,\"sourceHeading\":\"Module self-check\",\"checks\":[{\"id\":\"declared_hook\",\"text\":\"every webhook consumed by the app has a declared safe hook ID\"},{\"id\":\"signing_ref_declared\",\"text\":\"every hook signing reference exists in `app_secrets@1`\"},{\"id\":\"bounded_inbound\",\"text\":\"body size, retention, and event count are bounded\"},{\"id\":\"verified_events_only\",\"text\":\"browser code consumes only verified events through managed status/poll/ack helpers\"},{\"id\":\"no_signing_secret_exposure\",\"text\":\"signing secrets are never embedded or returned to browser code\"},{\"id\":\"app_user_dependency\",\"text\":\"`authMode: \\\"app_user\\\"` also declares enabled `app_users@1` when used\"}]}},\"createdAt\":\"2026-09-21T10:50:00.000Z\",\"updatedAt\":\"2026-09-21T10:50:00.000Z\"},{\"capabilityKey\":\"external_api_proxy@1\",\"instructionModuleId\":\"aqteron.capability.external_api_proxy@1\",\"instructionModuleVersionId\":\"aqteron.capability.external_api_proxy@1@0.1.0\",\"registryStatus\":\"available\",\"displayName\":\"External API Proxy\",\"summary\":\"Allowlisted bounded HTTPS calls with server-held authentication and SSRF protection.\",\"metadata\":{\"runtimeStatus\":\"runtime_available\",\"builderSelectable\":true,\"instructionVisible\":true,\"entitlementAuthority\":\"aqteron_validator_runtime\",\"presentation\":{\"locales\":{\"en\":{\"name\":\"External API Proxy\",\"summary\":\"Allowlisted bounded HTTPS calls with server-held authentication and SSRF protection.\"},\"fr\":{\"name\":\"Proxy d'API externe\",\"summary\":\"Appels HTTPS limités vers des domaines autorisés, avec authentification côté serveur et protection SSRF.\"},\"ru\":{\"name\":\"Прокси внешнего API\",\"summary\":\"Ограниченные HTTPS-вызовы к разрешённым доменам с серверной аутентификацией и защитой от SSRF.\"}}},\"sourcePath\":\"capabilities/EXTERNAL_API_PROXY.md\",\"selectionMetadata\":{\"schemaVersion\":\"aqteron.builder.selection_metadata.v1\",\"summary\":\"Allowlisted bounded HTTPS calls with server-held authentication and SSRF protection.\",\"userNeeds\":[\"call a specific approved external HTTPS API\",\"use server-held authentication for a third-party provider\",\"keep outbound network access bounded and auditable\"],\"selectionSignals\":[\"the workflow explicitly depends on one or more known public API domains\",\"declared methods, body sizes, timeouts, and quotas are sufficient\",\"the provider can be called without arbitrary headers or redirects\"],\"exclusions\":[\"arbitrary internet access, crawling, private/internal URLs, custom ports, raw sockets, or browser automation\",\"client-supplied Authorization/Cookie headers or absolute URLs\"],\"dependencies\":[\"app_secrets@1\"],\"compatibility\":{\"contracts\":[\"Aqteron PWA v1\"],\"requires\":[\"app_secrets@1\"],\"conflicts\":[]},\"runtime\":{\"adapterId\":\"external_api_proxy@1\"},\"availability\":{\"instructionStatus\":\"draft\",\"registryStatus\":\"available\",\"runtimeStatus\":\"runtime_available\",\"builderSelectable\":true,\"instructionVisible\":true,\"entitlementAuthority\":\"aqteron_validator_runtime\",\"notSelectableReason\":null}},\"selfCheckMetadata\":{\"schemaVersion\":\"aqteron.builder.module_self_check.v1\",\"instructionModuleId\":\"aqteron.capability.external_api_proxy@1\",\"moduleKind\":\"capability\",\"required\":true,\"appliesWhenSelected\":true,\"sourceHeading\":\"Module self-check\",\"checks\":[{\"id\":\"declared_domain_method\",\"text\":\"every external API domain and HTTP method used by the app is explicitly declared\"},{\"id\":\"server_held_auth\",\"text\":\"authentication uses only declared `app_secrets@1` references\"},{\"id\":\"relative_request_only\",\"text\":\"generated code sends only domain, method, relative path, bounded query, and optional JSON body\"},{\"id\":\"no_client_headers_or_url\",\"text\":\"no absolute URL, arbitrary headers, Authorization/Cookie value, protocol, port, host override, or IP target is client supplied\"},{\"id\":\"bounded_network_limits\",\"text\":\"timeout, request bytes, response bytes, and requests-per-minute quota are declared and bounded\"},{\"id\":\"app_user_dependency\",\"text\":\"`authMode: \\\"app_user\\\"` also declares enabled `app_users@1`\"},{\"id\":\"managed_helper_only\",\"text\":\"generated code uses only the managed external API helper\"}]}},\"createdAt\":\"2026-09-21T10:50:00.000Z\",\"updatedAt\":\"2026-09-21T10:50:00.000Z\"},{\"capabilityKey\":\"push_notifications@1\",\"instructionModuleId\":\"aqteron.capability.push_notifications@1\",\"instructionModuleVersionId\":\"aqteron.capability.push_notifications@1@0.1.5\",\"registryStatus\":\"available\",\"displayName\":\"Push Notifications\",\"summary\":\"Platform-managed push notification subscription and declared trigger support.\",\"metadata\":{\"runtimeStatus\":\"runtime_available\",\"builderSelectable\":true,\"instructionVisible\":true,\"entitlementAuthority\":\"aqteron_validator_runtime\",\"presentation\":{\"locales\":{\"en\":{\"name\":\"Push Notifications\",\"summary\":\"Platform-managed push notification subscription and declared trigger support.\"},\"fr\":{\"name\":\"Notifications push\",\"summary\":\"Abonnements aux notifications push gérés par la plateforme et prise en charge des déclencheurs déclarés.\"},\"ru\":{\"name\":\"Push-уведомления\",\"summary\":\"Управляемые платформой подписки на push-уведомления и поддержка объявленных триггеров.\"}}},\"sourcePath\":\"capabilities/PUSH_NOTIFICATIONS.md\",\"selectionMetadata\":{\"schemaVersion\":\"aqteron.builder.selection_metadata.v1\",\"summary\":\"Platform-managed push notification subscription and declared trigger support.\",\"userNeeds\":[\"notify users while the installed or browser PWA is closed\",\"support declared message, reminder, or shared-data alerts\",\"let users subscribe, unsubscribe, and manage notification preferences\"],\"selectionSignals\":[\"user explicitly needs push or closed-app alerts\",\"notification trigger fits the supported platform contract\",\"helper-only subscription controls are sufficient\"],\"exclusions\":[\"custom service workers or direct push provider calls\",\"invented send endpoints or arbitrary server triggers\",\"storing browser subscription secrets in app state\"],\"dependencies\":[],\"compatibility\":{\"contracts\":[\"Aqteron PWA v1\"],\"requires\":[],\"conflicts\":[]},\"runtime\":{\"adapterId\":null},\"availability\":{\"instructionStatus\":\"draft\",\"registryStatus\":\"available\",\"runtimeStatus\":\"runtime_available\",\"builderSelectable\":true,\"instructionVisible\":true,\"entitlementAuthority\":\"aqteron_validator_runtime\",\"notSelectableReason\":null}},\"selfCheckMetadata\":{\"schemaVersion\":\"aqteron.builder.module_self_check.v1\",\"instructionModuleId\":\"aqteron.capability.push_notifications@1\",\"moduleKind\":\"capability\",\"required\":true,\"appliesWhenSelected\":true,\"sourceHeading\":\"Module self-check\",\"checks\":[{\"id\":\"declared_when_helper_used\",\"text\":\"`push_notifications@1` is declared when notifications helper is used\"},{\"id\":\"supported_methods_only\",\"text\":\"only supported helper methods are called and no `send()` exists\"},{\"id\":\"no_app_service_worker_or_provider\",\"text\":\"no application service worker or push-provider endpoint is included\"},{\"id\":\"identity_mode_flow\",\"text\":\"identity flow matches the app: with `app_users@1`, push uses the trusted app-user session and never calls `connectAccount()`; without it, legacy account linking and permission remain separate explicit user actions\"},{\"id\":\"no_client_recipient_identity_authority\",\"text\":\"no client-supplied user identity is treated as recipient ownership authority\"},{\"id\":\"declared_database_trigger_fields\",\"text\":\"triggers use declared `app_database.record.create` fields\"},{\"id\":\"push_create_trigger_uses_create_path\",\"text\":\"every `app_database.record.create` trigger record uses the `appDatabase.put` create path, including offline/deferred replay\"},{\"id\":\"bounded_trigger_fields\",\"text\":\"actor/target/click URL fields exist as bounded strings in the database schema\"},{\"id\":\"same_app_click_url\",\"text\":\"click URL is root-relative and same-app\"},{\"id\":\"bounded_non_private_content\",\"text\":\"notification title/body are bounded and do not expose private message contents\"},{\"id\":\"opaque_recipient_ids\",\"text\":\"opaque recipient IDs are not treated as secrets or modified\"}]}},\"createdAt\":\"2026-09-16T05:00:00.000Z\",\"updatedAt\":\"2026-09-21T05:10:00.000Z\"},{\"capabilityKey\":\"realtime_events@1\",\"instructionModuleId\":\"aqteron.capability.realtime_events@1\",\"instructionModuleVersionId\":\"aqteron.capability.realtime_events@1@0.1.1\",\"registryStatus\":\"available\",\"displayName\":\"Realtime Events\",\"summary\":\"Bounded app/user-scoped live update signals with reconnect and replay.\",\"metadata\":{\"runtimeStatus\":\"runtime_available\",\"builderSelectable\":true,\"instructionVisible\":true,\"entitlementAuthority\":\"aqteron_validator_runtime\",\"presentation\":{\"locales\":{\"en\":{\"name\":\"Realtime Events\",\"summary\":\"Bounded app/user-scoped live update signals with reconnect and replay.\"},\"fr\":{\"name\":\"Événements temps réel\",\"summary\":\"Signaux de mise à jour en temps réel limités, par application ou utilisateur, avec reconnexion et relecture.\"},\"ru\":{\"name\":\"События реального времени\",\"summary\":\"Ограниченные realtime-события приложения или пользователя с переподключением и повторным чтением.\"}}},\"sourcePath\":\"capabilities/REALTIME_EVENTS.md\",\"selectionMetadata\":{\"schemaVersion\":\"aqteron.builder.selection_metadata.v1\",\"summary\":\"Bounded app/user-scoped live update signals with reconnect and replay.\",\"userNeeds\":[\"update an already-open app quickly when durable shared state changes\",\"show message/status/read-state/presence changes without manual refresh\",\"replay a bounded window of missed live update signals after reconnect\"],\"selectionSignals\":[\"the workflow has multi-tab, multi-device, or multi-user live updates\",\"durable records remain in app_database@1 while realtime only signals changes\",\"bounded long-poll transport with replay is sufficient\"],\"exclusions\":[\"durable business-data history or unbounded event logs\",\"custom WebSocket/SSE servers or arbitrary backend realtime infrastructure\",\"large payloads, files, credentials, secrets, or raw session/user identity transport\"],\"dependencies\":[],\"compatibility\":{\"contracts\":[\"Aqteron PWA v1\"],\"requires\":[],\"conflicts\":[]},\"runtime\":{\"adapterId\":\"realtime_events@1\"},\"availability\":{\"instructionStatus\":\"draft\",\"registryStatus\":\"available\",\"runtimeStatus\":\"runtime_available\",\"builderSelectable\":true,\"instructionVisible\":true,\"entitlementAuthority\":\"aqteron_validator_runtime\",\"notSelectableReason\":null}},\"selfCheckMetadata\":{\"schemaVersion\":\"aqteron.builder.module_self_check.v1\",\"instructionModuleId\":\"aqteron.capability.realtime_events@1\",\"moduleKind\":\"capability\",\"required\":true,\"appliesWhenSelected\":true,\"sourceHeading\":\"Module self-check\",\"checks\":[{\"id\":\"declared_when_helper_used\",\"text\":\"`realtime_events@1` is declared whenever `realtimeEvents` is used\"},{\"id\":\"supported_methods_only\",\"text\":\"only the exact managed `status`, `publish`, `poll`, and `subscribe` helper methods are used\"},{\"id\":\"channels_types_declared\",\"text\":\"every used channel and event type is declared\"},{\"id\":\"bounded_limits\",\"text\":\"each channel has bounded retention, event count, and payload size within the exact platform limits\"},{\"id\":\"app_user_dependency\",\"text\":\"`app_user` channels also declare enabled `app_users@1`\"},{\"id\":\"no_client_authority\",\"text\":\"no client-supplied app/user/subject/session/storage identifier is used as authorization authority\"},{\"id\":\"durable_data_separate\",\"text\":\"durable business records remain in `app_database@1` or another appropriate durable capability\"},{\"id\":\"cursor_reset_refreshes\",\"text\":\"cursor reset causes an authoritative state refresh instead of guessing missing events\"},{\"id\":\"bounded_subscribe_retry\",\"text\":\"subscribe retry uses a bounded exponential backoff with a single in-flight poll\"},{\"id\":\"no_reconnect_amplification\",\"text\":\"reconnect preserves the cursor and does not republish replay/presence events automatically\"},{\"id\":\"presence_ephemeral\",\"text\":\"presence is treated only as an ephemeral hint\"},{\"id\":\"no_sensitive_payloads\",\"text\":\"realtime payloads contain no secrets, credentials, raw session tokens, files, or large/private record bodies\"}]}},\"createdAt\":\"2026-09-21T05:40:00.000Z\",\"updatedAt\":\"2026-09-22T04:20:00.000Z\"},{\"capabilityKey\":\"web_parser@1\",\"instructionModuleId\":\"aqteron.capability.web_parser@1\",\"instructionModuleVersionId\":\"aqteron.capability.web_parser@1@0.1.4\",\"registryStatus\":\"available\",\"displayName\":\"Web Parser\",\"summary\":\"Bounded readable-text parsing for explicitly approved public domains.\",\"metadata\":{\"runtimeStatus\":\"runtime_available\",\"builderSelectable\":true,\"instructionVisible\":true,\"entitlementAuthority\":\"aqteron_validator_runtime\",\"presentation\":{\"locales\":{\"en\":{\"name\":\"Web Parser\",\"summary\":\"Bounded readable-text parsing for explicitly approved public domains.\"},\"fr\":{\"name\":\"Analyseur web\",\"summary\":\"Extraction limitée de texte lisible depuis des domaines publics explicitement approuvés.\"},\"ru\":{\"name\":\"Веб-парсер\",\"summary\":\"Ограниченное извлечение читаемого текста с явно разрешённых публичных доменов.\"}}},\"sourcePath\":\"capabilities/WEB_PARSER.md\",\"selectionMetadata\":{\"schemaVersion\":\"aqteron.builder.selection_metadata.v1\",\"summary\":\"Bounded readable-text parsing for explicitly approved public domains.\",\"userNeeds\":[\"read sanitized text from approved public HTTP(S) pages\",\"extract readable text from a specific public URL\",\"use public web text inside an Aqteron workflow\"],\"selectionSignals\":[\"live generation context marks this module usable for the account\",\"source pages are public, readable, and approved\",\"readable_text output is sufficient\"],\"exclusions\":[\"login-only, private, internal, localhost, or metadata URLs\",\"broad crawling, screenshots, binary downloads, raw HTML execution, or browser automation\"],\"dependencies\":[],\"compatibility\":{\"contracts\":[\"Aqteron PWA v1\"],\"requires\":[],\"conflicts\":[]},\"runtime\":{\"adapterId\":\"web_parser@1\"},\"availability\":{\"instructionStatus\":\"draft\",\"registryStatus\":\"available\",\"runtimeStatus\":\"runtime_available\",\"builderSelectable\":true,\"instructionVisible\":true,\"entitlementAuthority\":\"aqteron_validator_runtime\",\"notSelectableReason\":null}},\"selfCheckMetadata\":{\"schemaVersion\":\"aqteron.builder.module_self_check.v1\",\"instructionModuleId\":\"aqteron.capability.web_parser@1\",\"moduleKind\":\"capability\",\"required\":true,\"appliesWhenSelected\":true,\"sourceHeading\":\"Module self-check\",\"checks\":[{\"id\":\"workflow_needs_public_text\",\"text\":\"the user workflow genuinely needs public readable text\"},{\"id\":\"requested_domains_declared\",\"text\":\"every requested domain is explicitly declared\"},{\"id\":\"readable_text_only\",\"text\":\"only `readable_text` is requested\"},{\"id\":\"no_login_or_auth_forwarding\",\"text\":\"no login/session/cookie/Auth forwarding is attempted\"},{\"id\":\"no_private_targets\",\"text\":\"no private/internal/localhost/IP target is accepted\"},{\"id\":\"no_direct_scraping\",\"text\":\"no direct cross-origin scraping/headless crawling is implemented\"},{\"id\":\"declaration_request_agree\",\"text\":\"capability declaration and request URL agree\"},{\"id\":\"platform_errors_user_facing\",\"text\":\"platform errors are shown in user-facing form\"}]}},\"createdAt\":\"2026-09-16T05:00:00.000Z\",\"updatedAt\":\"2026-09-16T05:00:00.000Z\"},{\"capabilityKey\":\"webrtc_signaling@1\",\"instructionModuleId\":\"aqteron.capability.webrtc_signaling@1\",\"instructionModuleVersionId\":\"aqteron.capability.webrtc_signaling@1@0.1.6\",\"registryStatus\":\"available\",\"displayName\":\"WebRTC Signaling\",\"summary\":\"Short-lived app-scoped signaling for browser peer-to-peer WebRTC setup.\",\"metadata\":{\"runtimeStatus\":\"runtime_available\",\"builderSelectable\":true,\"instructionVisible\":true,\"entitlementAuthority\":\"aqteron_validator_runtime\",\"presentation\":{\"locales\":{\"en\":{\"name\":\"WebRTC Signaling\",\"summary\":\"Short-lived app-scoped signaling for browser peer-to-peer WebRTC setup.\"},\"fr\":{\"name\":\"Signalisation WebRTC\",\"summary\":\"Signalisation temporaire propre à l'application pour établir des connexions WebRTC pair à pair.\"},\"ru\":{\"name\":\"Сигналинг WebRTC\",\"summary\":\"Краткоживущий сигналинг приложения для установки браузерных WebRTC-соединений peer-to-peer.\"}}},\"sourcePath\":\"capabilities/WEBRTC_SIGNALING.md\",\"selectionMetadata\":{\"schemaVersion\":\"aqteron.builder.selection_metadata.v1\",\"summary\":\"Short-lived app-scoped signaling for browser peer-to-peer WebRTC setup.\",\"userNeeds\":[\"coordinate browser peer-to-peer audio, video, or data channel setup\",\"exchange short-lived WebRTC signaling messages\",\"support real-time peer connection workflows\"],\"selectionSignals\":[\"live generation context marks this module usable for the account\",\"application needs WebRTC signaling with platform-managed relay fallback when direct connectivity fails\",\"short-lived helper-mediated signaling and managed ICE credentials are sufficient\"],\"exclusions\":[\"media recording, SFU/media processing, custom TURN/STUN credential management, or persistent chat storage\",\"storing SDP or ICE payloads in app_database@1\"],\"dependencies\":[],\"compatibility\":{\"contracts\":[\"Aqteron PWA v1\"],\"requires\":[],\"conflicts\":[]},\"runtime\":{\"adapterId\":\"webrtc_signaling@1\"},\"availability\":{\"instructionStatus\":\"draft\",\"registryStatus\":\"available\",\"runtimeStatus\":\"runtime_available\",\"builderSelectable\":true,\"instructionVisible\":true,\"entitlementAuthority\":\"aqteron_validator_runtime\",\"notSelectableReason\":null}},\"selfCheckMetadata\":{\"schemaVersion\":\"aqteron.builder.module_self_check.v1\",\"instructionModuleId\":\"aqteron.capability.webrtc_signaling@1\",\"moduleKind\":\"capability\",\"required\":true,\"appliesWhenSelected\":true,\"sourceHeading\":\"Module self-check\",\"checks\":[{\"id\":\"declared_when_helper_used\",\"text\":\"the capability is declared if signaling helper is used\"},{\"id\":\"signaling_not_database_persisted\",\"text\":\"signaling data is not persisted in `app_database@1`\"},{\"id\":\"no_custom_signaling_route\",\"text\":\"no private/custom signaling server route is invented\"},{\"id\":\"bounded_payload_and_ttl\",\"text\":\"payload size and TTL are bounded\"},{\"id\":\"managed_turn_media_boundary\",\"text\":\"media remains browser WebRTC traffic; managed TURN is only an encrypted-packet relay and is not recording or media processing\"},{\"id\":\"managed_turn_helper_only\",\"text\":\"ICE configuration comes only from the platform helper; no hardcoded relay credentials or routes are embedded\"},{\"id\":\"managed_turn_ephemeral\",\"text\":\"short-lived managed TURN credentials are never persisted and are refreshed for new/recovered calls\"},{\"id\":\"participant_resume_bounded\",\"text\":\"participant recovery uses only the server-issued volatile `resumeToken` and bounded `participant.resume` retries\"},{\"id\":\"app_user_resume_continuity\",\"text\":\"app-user-bound participants cannot resume as a different trusted app user\"},{\"id\":\"no_blind_signal_retry\",\"text\":\"non-idempotent signaling sends are not blindly retried\"},{\"id\":\"recovery_cursor_continuity\",\"text\":\"recovery continues from the last signaling sequence rather than replaying from zero\"},{\"id\":\"visible_failure_states\",\"text\":\"call failure and unsupported-environment states are shown to the user\"}]}},\"createdAt\":\"2026-09-16T05:00:00.000Z\",\"updatedAt\":\"2026-09-22T04:20:00.000Z\"}]}",
    "metadata": {
      "taskId": "BLOCK14-REALTIME-CALL-RELIABILITY",
      "releaseVersion": "0.2.20-rc.1",
      "immutableComposition": true,
      "active": false,
      "published": false,
      "instructionSet": {
        "id": "aqteron.app-generation",
        "key": "aqteron.app-generation",
        "version": "0.2.20",
        "status": "draft",
        "contract": "Aqteron PWA v1",
        "runtimeSourceOfTruth": "aqteron_server_database",
        "sourceMetadata": {
          "status": "draft",
          "version": "0.2.20",
          "contract": "Aqteron PWA v1",
          "runtimeSourceOfTruth": "aqteron_server_database",
          "repositoryRole": "development_seed_export_snapshot",
          "registryMode": "database_discovery",
          "architecture": "SERVER_INSTRUCTION_ARCHITECTURE.md",
          "bootstrapDraft": "BOOTSTRAP.md",
          "capabilityPreflight": {
            "schemaVersion": "aqteron.capability_preflight_handoff.v1",
            "cabinetPath": "/cabinet/apps",
            "hashRoute": "capability-preflight",
            "capabilityIdParameter": "id",
            "maxCapabilityIds": 50,
            "maxCapabilityIdLength": 128,
            "authenticated": true
          },
          "sourcePath": "instruction-set.json",
          "generationHandoff": {
            "schemaVersion": "aqteron.generation_handoff.v1",
            "responseSchemaVersion": "aqteron.generation_handoff_response.v1",
            "capabilitySnapshotSchemaVersion": "aqteron.account_capability_snapshot.v1",
            "authenticatedAccountRequired": true,
            "accountSpecific": true,
            "authorizationSemantics": "composition_data_only",
            "finalAuthority": [
              "upload_validation",
              "runtime_validation"
            ],
            "allCapabilitiesRequest": {
              "method": "GET",
              "endpoint": "/api/me/generation-handoff",
              "scope": "all_generation_capabilities"
            },
            "exactCapabilitySetRequest": {
              "method": "POST",
              "endpoint": "/api/me/generation-handoff",
              "scope": "exact_capability_set",
              "capabilityIdsRequired": true,
              "emptyCapabilityIdsValid": true,
              "requiredBeforeFinalZip": true
            },
            "freshness": {
              "checkedAtRequired": true,
              "expiresAtRequired": true,
              "refreshWhenExpired": true
            },
            "fallbackMode": "none"
          },
          "generationContext": {
            "schemaVersion": "aqteron.ai_generation_context.v1",
            "deliveryMode": "official_server_resolved_locator",
            "authenticatedAccountPresenceSatisfied": true,
            "embeddedCapabilityPreflight": true,
            "secondManualAccountHandoffRequired": false,
            "zeroCapabilityGenerationAllowed": true,
            "arbitraryPastedJsonAccepted": false,
            "publicDiscoverySatisfiesAccountGate": false,
            "legacyNonContextGate": "authenticated_snapshot_or_exact_preflight",
            "capabilitySelectionMode": "choose_only_generation_usable_with_included_module",
            "responseLanguageHint": "cabinet_locale_overridden_by_newer_substantive_user_language",
            "managedFilesPolicy": "select_app_files_for_private_server_backed_files_without_silent_local_fallback",
            "snapshotNotAuthorization": true,
            "uploadRuntimeRevalidationRequired": true,
            "appUsersPolicy": "select_app_users_for_app_local_identity_without_custom_auth_or_aqteron_account_coupling",
            "trustedAppUserCapabilityBindingPolicy": "when app_users@1 is selected, bind per-user managed capability authority only to server-trusted app-user session state; never client-selected user identity",
            "realtimeEventsPolicy": "select_realtime_events_for_short_lived_live_update_signals_with_bounded_replay_and_server_derived_app_user_scope",
            "realtimeReliabilityPolicy": "reconnect long-poll with one in-flight request, bounded exponential backoff and preserved cursors; never republish replay or presence merely because transport reconnects",
            "managedTurnPolicy": "for WebRTC, obtain ICE servers only from the Aqteron helper; managed TURN credentials are short-lived, server-issued, app/environment-bound, never embedded or persisted",
            "webrtcRecoveryPolicy": "keep resume tokens volatile; use bounded participant resume/heartbeat retries, preserve signaling cursors, refresh ICE on recovery and never blind-retry non-idempotent signal sends",
            "secretsPolicy": "select app_secrets only for server-held named credential references; never embed or expose raw secret values",
            "externalApiProxyPolicy": "select external_api_proxy only for explicitly allowlisted HTTPS APIs with bounded methods, sizes, timeouts and quotas",
            "webhooksPolicy": "select app_webhooks only for signed bounded inbound JSON events using server-held signing references",
            "jobsPolicy": "select app_jobs only for bounded delayed/retryable external API actions; never raw credentials or arbitrary backend code"
          }
        }
      },
      "modulePins": [
        {
          "instructionModuleId": "aqteron.builder.core",
          "moduleKey": "aqteron.builder.core",
          "moduleKind": "core",
          "sourcePath": "BUILDER_CORE.md",
          "instructionModuleVersionId": "aqteron.builder.core@0.2.6",
          "versionLabel": "0.2.6",
          "contentSha256": "c15131e44427fb0f47a422e4fa46e7c1da75ddec0848b8a5d7a8c1eb0d62f8aa",
          "status": "draft",
          "contract": "Aqteron PWA v1",
          "selectionMetadata": null,
          "capabilityAvailability": null,
          "selfCheckMetadata": null
        },
        {
          "instructionModuleId": "aqteron.capability.app_database@1",
          "moduleKey": "aqteron.capability.app_database@1",
          "moduleKind": "capability",
          "sourcePath": "capabilities/APP_DATABASE.md",
          "instructionModuleVersionId": "aqteron.capability.app_database@1@0.1.5",
          "versionLabel": "0.1.5",
          "contentSha256": "52e1ab38d67951ff4c4840fd0212ac1bf86a4f883d218d20d3589564c6caa2f6",
          "status": "draft",
          "contract": "Aqteron PWA v1",
          "selectionMetadata": {
            "schemaVersion": "aqteron.builder.selection_metadata.v1",
            "summary": "App-scoped JSON record storage for shared or cross-device persistence.",
            "userNeeds": [
              "persist structured records beyond one browser or install",
              "share app-scoped records across linked users or devices",
              "store bounded server-side JSON records"
            ],
            "selectionSignals": [
              "localStorage or IndexedDB is insufficient",
              "records must survive reinstall or device changes",
              "multiple users or devices need the same app data"
            ],
            "exclusions": [
              "file, image, document, or attachment storage",
              "raw SQL or arbitrary backend database access",
              "secrets, credentials, passwords, tokens, or private keys"
            ],
            "dependencies": [],
            "compatibility": {
              "contracts": [
                "Aqteron PWA v1"
              ],
              "requires": [],
              "conflicts": []
            },
            "runtime": {
              "adapterId": "app_database@1"
            },
            "availability": {
              "instructionStatus": "draft",
              "registryStatus": "available",
              "runtimeStatus": "runtime_available",
              "builderSelectable": true,
              "instructionVisible": true,
              "entitlementAuthority": "aqteron_validator_runtime",
              "notSelectableReason": null
            }
          },
          "capabilityAvailability": {
            "capabilityKey": "app_database@1",
            "registryStatus": "available",
            "runtimeStatus": "runtime_available",
            "builderSelectable": true,
            "instructionVisible": true,
            "entitlementAuthority": "aqteron_validator_runtime"
          },
          "selfCheckMetadata": {
            "schemaVersion": "aqteron.builder.module_self_check.v1",
            "instructionModuleId": "aqteron.capability.app_database@1",
            "moduleKind": "capability",
            "required": true,
            "appliesWhenSelected": true,
            "sourceHeading": "Module self-check",
            "checks": [
              {
                "id": "declared_when_helper_used",
                "text": "capability is declared when JavaScript uses `appDatabase`"
              },
              {
                "id": "used_collections_declared",
                "text": "every used collection is declared"
              },
              {
                "id": "schema_keys_match",
                "text": "schema and JS keys are identical lower_snake_case ASCII"
              },
              {
                "id": "no_undeclared_fields",
                "text": "no undeclared extra fields are written"
              },
              {
                "id": "new_record_uses_put",
                "text": "every new logical record uses `put` with declared `record.create`"
              },
              {
                "id": "existing_record_uses_set",
                "text": "every existing logical record update uses `set` with declared `record.update`"
              },
              {
                "id": "offline_replay_preserves_intent",
                "text": "offline/deferred replay preserves `put` versus `set` operation intent"
              },
              {
                "id": "bounded_list_limit",
                "text": "every `list` call has an explicit numeric limit from 1 to 100"
              },
              {
                "id": "db_list_limit_not_record_quota",
                "text": "a `list` retrieval limit is not treated as the collection `maxRecords` quota"
              },
              {
                "id": "no_raw_secrets",
                "text": "no raw secrets are persisted"
              },
              {
                "id": "no_private_database_routes",
                "text": "no direct/private database routes or raw SQL are used"
              },
              {
                "id": "app_user_server_authority",
                "text": "when `authMode: \"app_user\"` is selected, `app_users@1` is enabled and authorization comes only from the trusted server-resolved app-user session"
              },
              {
                "id": "no_client_identity_or_row_privacy_claim",
                "text": "no client-supplied user identity is treated as authority and no row-level privacy is claimed from `authMode` alone"
              },
              {
                "id": "user_readable_errors",
                "text": "capability failures produce user-readable UI errors"
              }
            ]
          }
        },
        {
          "instructionModuleId": "aqteron.capability.app_files@1",
          "moduleKey": "aqteron.capability.app_files@1",
          "moduleKind": "capability",
          "sourcePath": "capabilities/APP_FILES.md",
          "instructionModuleVersionId": "aqteron.capability.app_files@1@0.3.1",
          "versionLabel": "0.3.1",
          "contentSha256": "3c184d3714879bedcbdb009e553667034902170d6677589b2b5d05f4bfb14541",
          "status": "activation_candidate",
          "contract": "Aqteron PWA v1",
          "selectionMetadata": {
            "schemaVersion": "aqteron.builder.selection_metadata.v1",
            "summary": "Guarded private file storage for entitled applications when canonical readiness controls pass.",
            "userNeeds": [
              "store user files, attachments, images, documents, imports, or exports",
              "keep private application-scoped files in managed storage",
              "associate files with app workflows"
            ],
            "selectionSignals": [
              "managed private files are required and server-side entitlement is available",
              "files must persist outside local browser storage",
              "workflow references uploaded or generated files"
            ],
            "exclusions": [
              "workflows that can remain entirely in local browser storage",
              "public hosting or public URL generation",
              "shared-drive behavior across unrelated apps or users",
              "structured JSON record storage without files"
            ],
            "dependencies": [],
            "compatibility": {
              "contracts": [
                "Aqteron PWA v1"
              ],
              "requires": [],
              "conflicts": []
            },
            "runtime": {
              "adapterId": "app_files@1"
            },
            "availability": {
              "instructionStatus": "activation_candidate",
              "registryStatus": "available",
              "runtimeStatus": "runtime_available",
              "builderSelectable": true,
              "instructionVisible": true,
              "entitlementAuthority": "aqteron_validator_runtime",
              "notSelectableReason": null
            }
          },
          "capabilityAvailability": {
            "capabilityKey": "app_files@1",
            "registryStatus": "available",
            "runtimeStatus": "runtime_available",
            "builderSelectable": true,
            "instructionVisible": true,
            "entitlementAuthority": "aqteron_validator_runtime"
          },
          "selfCheckMetadata": {
            "schemaVersion": "aqteron.builder.module_self_check.v1",
            "instructionModuleId": "aqteron.capability.app_files@1",
            "moduleKind": "capability",
            "required": true,
            "appliesWhenSelected": true,
            "sourceHeading": "Module self-check",
            "checks": [
              {
                "id": "declared_when_helper_used",
                "text": "capability is declared if `appFiles` is used"
              },
              {
                "id": "only_prompt2app_helper",
                "text": "only the exact `window.Prompt2App.appFiles` methods above are used"
              },
              {
                "id": "subject_mode_identity_matches",
                "text": "identity handling matches the declared subject mode: `app_user` requires trusted app-local sign-in, `app` does not account-link, and only legacy no-`subjectMode` declarations may call `connectAccount()`"
              },
              {
                "id": "no_client_file_identity_authority",
                "text": "no client-provided user/subject identifier is used as file authorization authority"
              },
              {
                "id": "used_buckets_declared_private",
                "text": "every used bucket is declared and private"
              },
              {
                "id": "file_quota_dimensions_coherent",
                "text": "MIME types are bounded and `maxFileSizeBytes`, `maxTotalBytes`, and `maxFiles` are validated as separate dimensions within their exact ceilings"
              },
              {
                "id": "mixed_db_files_fixture_coherent",
                "text": "mixed database/file workflows keep database `list` limits, database `maxRecords`, and file `maxFiles` distinct and dimensionally coherent"
              },
              {
                "id": "exact_file_transport",
                "text": "file inputs are browser `File` values and downloads use `contentBase64`"
              },
              {
                "id": "no_invented_storage_authority",
                "text": "no public/presigned/storage URLs, filesystem paths, internal metadata, or unsupported sharing are invented"
              },
              {
                "id": "server_entitlement_authority",
                "text": "server entitlement is never inferred from the package"
              },
              {
                "id": "visible_errors",
                "text": "errors are visible and do not falsely report successful storage"
              }
            ]
          }
        },
        {
          "instructionModuleId": "aqteron.capability.app_jobs@1",
          "moduleKey": "aqteron.capability.app_jobs@1",
          "moduleKind": "capability",
          "sourcePath": "capabilities/APP_JOBS.md",
          "instructionModuleVersionId": "aqteron.capability.app_jobs@1@0.1.0",
          "versionLabel": "0.1.0",
          "contentSha256": "bbecf7d4dbb15939472be98dc253825c383cce1a7030ca62cd68c283903c84d6",
          "status": "draft",
          "contract": "Aqteron PWA v1",
          "selectionMetadata": {
            "schemaVersion": "aqteron.builder.selection_metadata.v1",
            "summary": "Bounded delayed and retryable external API actions executed by a managed worker.",
            "userNeeds": [
              "run an approved external API action later",
              "retry transient external API failures with bounded backoff",
              "inspect and cancel pending managed jobs"
            ],
            "selectionSignals": [
              "the scheduled work is representable as an external_api_proxy request descriptor",
              "one-time delayed execution and bounded retries are sufficient"
            ],
            "exclusions": [
              "arbitrary code execution, cron scripts, unbounded recurring tasks, raw secrets in payloads, or custom background servers"
            ],
            "dependencies": [
              "external_api_proxy@1",
              "app_secrets@1"
            ],
            "compatibility": {
              "contracts": [
                "Aqteron PWA v1"
              ],
              "requires": [
                "external_api_proxy@1",
                "app_secrets@1"
              ],
              "conflicts": []
            },
            "runtime": {
              "adapterId": "app_jobs@1"
            },
            "availability": {
              "instructionStatus": "draft",
              "registryStatus": "available",
              "runtimeStatus": "runtime_available",
              "builderSelectable": true,
              "instructionVisible": true,
              "entitlementAuthority": "aqteron_validator_runtime",
              "notSelectableReason": null
            }
          },
          "capabilityAvailability": {
            "capabilityKey": "app_jobs@1",
            "registryStatus": "available",
            "runtimeStatus": "runtime_available",
            "builderSelectable": true,
            "instructionVisible": true,
            "entitlementAuthority": "aqteron_validator_runtime"
          },
          "selfCheckMetadata": {
            "schemaVersion": "aqteron.builder.module_self_check.v1",
            "instructionModuleId": "aqteron.capability.app_jobs@1",
            "moduleKind": "capability",
            "required": true,
            "appliesWhenSelected": true,
            "sourceHeading": "Module self-check",
            "checks": [
              {
                "id": "dependencies_declared",
                "text": "`external_api_proxy@1` and required `app_secrets@1` references are declared"
              },
              {
                "id": "request_allowlisted",
                "text": "every scheduled request satisfies the declared external API domain and method allowlist"
              },
              {
                "id": "bounded_schedule",
                "text": "run time, queue size, retry count, and retry delay stay inside declared bounds"
              },
              {
                "id": "idempotency_key",
                "text": "each logical scheduled action uses a stable non-secret idempotency key"
              },
              {
                "id": "no_raw_credentials",
                "text": "scheduled job payloads contain no raw credentials or arbitrary backend code"
              },
              {
                "id": "app_user_dependency",
                "text": "`authMode: \"app_user\"` also declares enabled `app_users@1`"
              },
              {
                "id": "managed_helper_only",
                "text": "generated code uses only the managed job status/schedule/list/get/cancel helpers"
              }
            ]
          }
        },
        {
          "instructionModuleId": "aqteron.capability.app_secrets@1",
          "moduleKey": "aqteron.capability.app_secrets@1",
          "moduleKind": "capability",
          "sourcePath": "capabilities/APP_SECRETS.md",
          "instructionModuleVersionId": "aqteron.capability.app_secrets@1@0.1.0",
          "versionLabel": "0.1.0",
          "contentSha256": "f1b161d9d941227f90feeebc9634838384b36de590e756fa813c5e44b1509fd6",
          "status": "draft",
          "contract": "Aqteron PWA v1",
          "selectionMetadata": {
            "schemaVersion": "aqteron.builder.selection_metadata.v1",
            "summary": "Server-held encrypted credential references that are never exposed to generated app JavaScript.",
            "userNeeds": [
              "store third-party API credentials without exposing them to browser code",
              "let the app owner configure named server-held credential references",
              "rotate or revoke integration credentials without rebuilding the application"
            ],
            "selectionSignals": [
              "an external integration needs an API key, token, or signing secret",
              "the credential must remain server-side",
              "the user can configure the credential after publication"
            ],
            "exclusions": [
              "embedding raw credentials in ZIP files, metadata, JavaScript, browser storage, logs, or job payloads",
              "using app_secrets as general user data storage"
            ],
            "dependencies": [],
            "compatibility": {
              "contracts": [
                "Aqteron PWA v1"
              ],
              "requires": [],
              "conflicts": []
            },
            "runtime": {
              "adapterId": "app_secrets@1"
            },
            "availability": {
              "instructionStatus": "draft",
              "registryStatus": "available",
              "runtimeStatus": "runtime_available",
              "builderSelectable": true,
              "instructionVisible": true,
              "entitlementAuthority": "aqteron_validator_runtime",
              "notSelectableReason": null
            }
          },
          "capabilityAvailability": {
            "capabilityKey": "app_secrets@1",
            "registryStatus": "available",
            "runtimeStatus": "runtime_available",
            "builderSelectable": true,
            "instructionVisible": true,
            "entitlementAuthority": "aqteron_validator_runtime"
          },
          "selfCheckMetadata": {
            "schemaVersion": "aqteron.builder.module_self_check.v1",
            "instructionModuleId": "aqteron.capability.app_secrets@1",
            "moduleKind": "capability",
            "required": true,
            "appliesWhenSelected": true,
            "sourceHeading": "Module self-check",
            "checks": [
              {
                "id": "declared_when_needed",
                "text": "`app_secrets@1` is declared whenever server-held integration credentials are required"
              },
              {
                "id": "refs_declared",
                "text": "every credential reference used by another capability is declared in `config.refs`"
              },
              {
                "id": "no_raw_secret_in_package",
                "text": "no raw secret value appears in ZIP files, metadata, JavaScript, browser storage, logs, webhook payloads, or job payloads"
              },
              {
                "id": "status_only_browser",
                "text": "generated app code uses only status visibility and never expects a raw secret value"
              },
              {
                "id": "owner_configuration",
                "text": "the user-facing flow explains that the application owner configures the credential in Aqteron"
              },
              {
                "id": "rotation_safe",
                "text": "rotation or revocation does not require rebuilding the generated application"
              }
            ]
          }
        },
        {
          "instructionModuleId": "aqteron.capability.app_users@1",
          "moduleKey": "aqteron.capability.app_users@1",
          "moduleKind": "capability",
          "sourcePath": "capabilities/APP_USERS.md",
          "instructionModuleVersionId": "aqteron.capability.app_users@1@0.1.1",
          "versionLabel": "0.1.1",
          "contentSha256": "39de99146570c81ada8d019b085101d83f86d6ec03dccb3cace5a3a363c96dab",
          "status": "draft",
          "contract": "Aqteron PWA v1",
          "selectionMetadata": {
            "schemaVersion": "aqteron.builder.selection_metadata.v1",
            "summary": "Isolated application-local user accounts, sessions, roles, permissions, and credential recovery.",
            "userNeeds": [
              "let visitors create or use accounts that belong only to the application",
              "maintain application-local sign-in sessions across visits",
              "check application-local roles or permissions"
            ],
            "selectionSignals": [
              "the requested workflow needs sign-in that must not depend on Aqteron platform accounts",
              "multiple end users need distinct identities inside one published application",
              "managed credential hashing, lockout, recovery, or session revocation is required"
            ],
            "exclusions": [
              "Aqteron platform account authentication or account linking",
              "custom authentication servers or direct credential storage",
              "workflows that need no user identity"
            ],
            "dependencies": [],
            "compatibility": {
              "contracts": [
                "Aqteron PWA v1"
              ],
              "requires": [],
              "conflicts": []
            },
            "runtime": {
              "adapterId": "app_users@1"
            },
            "availability": {
              "instructionStatus": "draft",
              "registryStatus": "available",
              "runtimeStatus": "runtime_available",
              "builderSelectable": true,
              "instructionVisible": true,
              "entitlementAuthority": "aqteron_validator_runtime",
              "notSelectableReason": null
            }
          },
          "capabilityAvailability": {
            "capabilityKey": "app_users@1",
            "registryStatus": "available",
            "runtimeStatus": "runtime_available",
            "builderSelectable": true,
            "instructionVisible": true,
            "entitlementAuthority": "aqteron_validator_runtime"
          },
          "selfCheckMetadata": {
            "schemaVersion": "aqteron.builder.module_self_check.v1",
            "instructionModuleId": "aqteron.capability.app_users@1",
            "moduleKind": "capability",
            "required": true,
            "appliesWhenSelected": true,
            "sourceHeading": "Module self-check",
            "checks": [
              {
                "id": "declared_when_helper_used",
                "text": "`app_users@1` is declared whenever `appUsers` is used"
              },
              {
                "id": "supported_methods_only",
                "text": "only the exact `window.Prompt2App.appUsers` public methods above are used"
              },
              {
                "id": "platform_identity_separate",
                "text": "app users are never treated as Aqteron platform accounts"
              },
              {
                "id": "no_custom_auth_backend",
                "text": "no custom authentication backend or private app-user route is invented"
              },
              {
                "id": "no_raw_auth_secrets",
                "text": "raw passwords, PINs, recovery codes, session tokens, and cookies are never persisted by generated code"
              },
              {
                "id": "registration_mode_matches",
                "text": "registration UI matches the declared `registrationMode`"
              },
              {
                "id": "bounded_security_policy",
                "text": "credential types and session/lockout bounds match the declaration contract"
              },
              {
                "id": "permission_boundary",
                "text": "permission checks do not rely on hiding UI as server authorization"
              },
              {
                "id": "admin_ops_not_public",
                "text": "role assignment and recovery-code issuance are not exposed as public browser operations"
              },
              {
                "id": "trusted_cross_capability_authority",
                "text": "capability combinations that require app-user authority derive it only from the trusted server session and never from client-selected user IDs"
              },
              {
                "id": "current_binding_modes",
                "text": "per-user files use `subjectMode: \"app_user\"`, database sign-in gates use `authMode: \"app_user\"`, and push does not account-link when `app_users@1` is enabled"
              },
              {
                "id": "visible_auth_states",
                "text": "authentication, lockout, recovery, and unavailable states are shown clearly to the user"
              }
            ]
          }
        },
        {
          "instructionModuleId": "aqteron.capability.app_webhooks@1",
          "moduleKey": "aqteron.capability.app_webhooks@1",
          "moduleKind": "capability",
          "sourcePath": "capabilities/APP_WEBHOOKS.md",
          "instructionModuleVersionId": "aqteron.capability.app_webhooks@1@0.1.0",
          "versionLabel": "0.1.0",
          "contentSha256": "ce9424ebce6996b5f6e3ef31ea7eb644e83644f2c46bcc22c01acede164749f1",
          "status": "draft",
          "contract": "Aqteron PWA v1",
          "selectionMetadata": {
            "schemaVersion": "aqteron.builder.selection_metadata.v1",
            "summary": "Verified bounded inbound JSON webhook events isolated per Application Environment.",
            "userNeeds": [
              "receive signed events from an external provider",
              "consume bounded verified JSON callbacks",
              "avoid exposing webhook signing material to browser code"
            ],
            "selectionSignals": [
              "the provider can send HMAC-SHA256 signed JSON to a stable app webhook endpoint",
              "bounded retention and polling are sufficient"
            ],
            "exclusions": [
              "unsigned callbacks, arbitrary request bodies, raw credential transport, or custom webhook servers"
            ],
            "dependencies": [
              "app_secrets@1"
            ],
            "compatibility": {
              "contracts": [
                "Aqteron PWA v1"
              ],
              "requires": [
                "app_secrets@1"
              ],
              "conflicts": []
            },
            "runtime": {
              "adapterId": "app_webhooks@1"
            },
            "availability": {
              "instructionStatus": "draft",
              "registryStatus": "available",
              "runtimeStatus": "runtime_available",
              "builderSelectable": true,
              "instructionVisible": true,
              "entitlementAuthority": "aqteron_validator_runtime",
              "notSelectableReason": null
            }
          },
          "capabilityAvailability": {
            "capabilityKey": "app_webhooks@1",
            "registryStatus": "available",
            "runtimeStatus": "runtime_available",
            "builderSelectable": true,
            "instructionVisible": true,
            "entitlementAuthority": "aqteron_validator_runtime"
          },
          "selfCheckMetadata": {
            "schemaVersion": "aqteron.builder.module_self_check.v1",
            "instructionModuleId": "aqteron.capability.app_webhooks@1",
            "moduleKind": "capability",
            "required": true,
            "appliesWhenSelected": true,
            "sourceHeading": "Module self-check",
            "checks": [
              {
                "id": "declared_hook",
                "text": "every webhook consumed by the app has a declared safe hook ID"
              },
              {
                "id": "signing_ref_declared",
                "text": "every hook signing reference exists in `app_secrets@1`"
              },
              {
                "id": "bounded_inbound",
                "text": "body size, retention, and event count are bounded"
              },
              {
                "id": "verified_events_only",
                "text": "browser code consumes only verified events through managed status/poll/ack helpers"
              },
              {
                "id": "no_signing_secret_exposure",
                "text": "signing secrets are never embedded or returned to browser code"
              },
              {
                "id": "app_user_dependency",
                "text": "`authMode: \"app_user\"` also declares enabled `app_users@1` when used"
              }
            ]
          }
        },
        {
          "instructionModuleId": "aqteron.capability.external_api_proxy@1",
          "moduleKey": "aqteron.capability.external_api_proxy@1",
          "moduleKind": "capability",
          "sourcePath": "capabilities/EXTERNAL_API_PROXY.md",
          "instructionModuleVersionId": "aqteron.capability.external_api_proxy@1@0.1.0",
          "versionLabel": "0.1.0",
          "contentSha256": "8b7dd25ec8359daedc3e7b7567d87b322054cbda9f24f13697ef435d3e9623e7",
          "status": "draft",
          "contract": "Aqteron PWA v1",
          "selectionMetadata": {
            "schemaVersion": "aqteron.builder.selection_metadata.v1",
            "summary": "Allowlisted bounded HTTPS calls with server-held authentication and SSRF protection.",
            "userNeeds": [
              "call a specific approved external HTTPS API",
              "use server-held authentication for a third-party provider",
              "keep outbound network access bounded and auditable"
            ],
            "selectionSignals": [
              "the workflow explicitly depends on one or more known public API domains",
              "declared methods, body sizes, timeouts, and quotas are sufficient",
              "the provider can be called without arbitrary headers or redirects"
            ],
            "exclusions": [
              "arbitrary internet access, crawling, private/internal URLs, custom ports, raw sockets, or browser automation",
              "client-supplied Authorization/Cookie headers or absolute URLs"
            ],
            "dependencies": [
              "app_secrets@1"
            ],
            "compatibility": {
              "contracts": [
                "Aqteron PWA v1"
              ],
              "requires": [
                "app_secrets@1"
              ],
              "conflicts": []
            },
            "runtime": {
              "adapterId": "external_api_proxy@1"
            },
            "availability": {
              "instructionStatus": "draft",
              "registryStatus": "available",
              "runtimeStatus": "runtime_available",
              "builderSelectable": true,
              "instructionVisible": true,
              "entitlementAuthority": "aqteron_validator_runtime",
              "notSelectableReason": null
            }
          },
          "capabilityAvailability": {
            "capabilityKey": "external_api_proxy@1",
            "registryStatus": "available",
            "runtimeStatus": "runtime_available",
            "builderSelectable": true,
            "instructionVisible": true,
            "entitlementAuthority": "aqteron_validator_runtime"
          },
          "selfCheckMetadata": {
            "schemaVersion": "aqteron.builder.module_self_check.v1",
            "instructionModuleId": "aqteron.capability.external_api_proxy@1",
            "moduleKind": "capability",
            "required": true,
            "appliesWhenSelected": true,
            "sourceHeading": "Module self-check",
            "checks": [
              {
                "id": "declared_domain_method",
                "text": "every external API domain and HTTP method used by the app is explicitly declared"
              },
              {
                "id": "server_held_auth",
                "text": "authentication uses only declared `app_secrets@1` references"
              },
              {
                "id": "relative_request_only",
                "text": "generated code sends only domain, method, relative path, bounded query, and optional JSON body"
              },
              {
                "id": "no_client_headers_or_url",
                "text": "no absolute URL, arbitrary headers, Authorization/Cookie value, protocol, port, host override, or IP target is client supplied"
              },
              {
                "id": "bounded_network_limits",
                "text": "timeout, request bytes, response bytes, and requests-per-minute quota are declared and bounded"
              },
              {
                "id": "app_user_dependency",
                "text": "`authMode: \"app_user\"` also declares enabled `app_users@1`"
              },
              {
                "id": "managed_helper_only",
                "text": "generated code uses only the managed external API helper"
              }
            ]
          }
        },
        {
          "instructionModuleId": "aqteron.capability.push_notifications@1",
          "moduleKey": "aqteron.capability.push_notifications@1",
          "moduleKind": "capability",
          "sourcePath": "capabilities/PUSH_NOTIFICATIONS.md",
          "instructionModuleVersionId": "aqteron.capability.push_notifications@1@0.1.5",
          "versionLabel": "0.1.5",
          "contentSha256": "dd8f2a4c793617b37a9afc1ab1fb9d28a515693e4ecc712cb83a594ac6304074",
          "status": "draft",
          "contract": "Aqteron PWA v1",
          "selectionMetadata": {
            "schemaVersion": "aqteron.builder.selection_metadata.v1",
            "summary": "Platform-managed push notification subscription and declared trigger support.",
            "userNeeds": [
              "notify users while the installed or browser PWA is closed",
              "support declared message, reminder, or shared-data alerts",
              "let users subscribe, unsubscribe, and manage notification preferences"
            ],
            "selectionSignals": [
              "user explicitly needs push or closed-app alerts",
              "notification trigger fits the supported platform contract",
              "helper-only subscription controls are sufficient"
            ],
            "exclusions": [
              "custom service workers or direct push provider calls",
              "invented send endpoints or arbitrary server triggers",
              "storing browser subscription secrets in app state"
            ],
            "dependencies": [],
            "compatibility": {
              "contracts": [
                "Aqteron PWA v1"
              ],
              "requires": [],
              "conflicts": []
            },
            "runtime": {
              "adapterId": null
            },
            "availability": {
              "instructionStatus": "draft",
              "registryStatus": "available",
              "runtimeStatus": "runtime_available",
              "builderSelectable": true,
              "instructionVisible": true,
              "entitlementAuthority": "aqteron_validator_runtime",
              "notSelectableReason": null
            }
          },
          "capabilityAvailability": {
            "capabilityKey": "push_notifications@1",
            "registryStatus": "available",
            "runtimeStatus": "runtime_available",
            "builderSelectable": true,
            "instructionVisible": true,
            "entitlementAuthority": "aqteron_validator_runtime"
          },
          "selfCheckMetadata": {
            "schemaVersion": "aqteron.builder.module_self_check.v1",
            "instructionModuleId": "aqteron.capability.push_notifications@1",
            "moduleKind": "capability",
            "required": true,
            "appliesWhenSelected": true,
            "sourceHeading": "Module self-check",
            "checks": [
              {
                "id": "declared_when_helper_used",
                "text": "`push_notifications@1` is declared when notifications helper is used"
              },
              {
                "id": "supported_methods_only",
                "text": "only supported helper methods are called and no `send()` exists"
              },
              {
                "id": "no_app_service_worker_or_provider",
                "text": "no application service worker or push-provider endpoint is included"
              },
              {
                "id": "identity_mode_flow",
                "text": "identity flow matches the app: with `app_users@1`, push uses the trusted app-user session and never calls `connectAccount()`; without it, legacy account linking and permission remain separate explicit user actions"
              },
              {
                "id": "no_client_recipient_identity_authority",
                "text": "no client-supplied user identity is treated as recipient ownership authority"
              },
              {
                "id": "declared_database_trigger_fields",
                "text": "triggers use declared `app_database.record.create` fields"
              },
              {
                "id": "push_create_trigger_uses_create_path",
                "text": "every `app_database.record.create` trigger record uses the `appDatabase.put` create path, including offline/deferred replay"
              },
              {
                "id": "bounded_trigger_fields",
                "text": "actor/target/click URL fields exist as bounded strings in the database schema"
              },
              {
                "id": "same_app_click_url",
                "text": "click URL is root-relative and same-app"
              },
              {
                "id": "bounded_non_private_content",
                "text": "notification title/body are bounded and do not expose private message contents"
              },
              {
                "id": "opaque_recipient_ids",
                "text": "opaque recipient IDs are not treated as secrets or modified"
              }
            ]
          }
        },
        {
          "instructionModuleId": "aqteron.capability.realtime_events@1",
          "moduleKey": "aqteron.capability.realtime_events@1",
          "moduleKind": "capability",
          "sourcePath": "capabilities/REALTIME_EVENTS.md",
          "instructionModuleVersionId": "aqteron.capability.realtime_events@1@0.1.1",
          "versionLabel": "0.1.1",
          "contentSha256": "6c1d3c59037e07d7bb4228d993f6a4ebecdf04e29d2680e008993e2c63b976e5",
          "status": "draft",
          "contract": "Aqteron PWA v1",
          "selectionMetadata": {
            "schemaVersion": "aqteron.builder.selection_metadata.v1",
            "summary": "Bounded app/user-scoped live update signals with reconnect and replay.",
            "userNeeds": [
              "update an already-open app quickly when durable shared state changes",
              "show message/status/read-state/presence changes without manual refresh",
              "replay a bounded window of missed live update signals after reconnect"
            ],
            "selectionSignals": [
              "the workflow has multi-tab, multi-device, or multi-user live updates",
              "durable records remain in app_database@1 while realtime only signals changes",
              "bounded long-poll transport with replay is sufficient"
            ],
            "exclusions": [
              "durable business-data history or unbounded event logs",
              "custom WebSocket/SSE servers or arbitrary backend realtime infrastructure",
              "large payloads, files, credentials, secrets, or raw session/user identity transport"
            ],
            "dependencies": [],
            "compatibility": {
              "contracts": [
                "Aqteron PWA v1"
              ],
              "requires": [],
              "conflicts": []
            },
            "runtime": {
              "adapterId": "realtime_events@1"
            },
            "availability": {
              "instructionStatus": "draft",
              "registryStatus": "available",
              "runtimeStatus": "runtime_available",
              "builderSelectable": true,
              "instructionVisible": true,
              "entitlementAuthority": "aqteron_validator_runtime",
              "notSelectableReason": null
            }
          },
          "capabilityAvailability": {
            "capabilityKey": "realtime_events@1",
            "registryStatus": "available",
            "runtimeStatus": "runtime_available",
            "builderSelectable": true,
            "instructionVisible": true,
            "entitlementAuthority": "aqteron_validator_runtime"
          },
          "selfCheckMetadata": {
            "schemaVersion": "aqteron.builder.module_self_check.v1",
            "instructionModuleId": "aqteron.capability.realtime_events@1",
            "moduleKind": "capability",
            "required": true,
            "appliesWhenSelected": true,
            "sourceHeading": "Module self-check",
            "checks": [
              {
                "id": "declared_when_helper_used",
                "text": "`realtime_events@1` is declared whenever `realtimeEvents` is used"
              },
              {
                "id": "supported_methods_only",
                "text": "only the exact managed `status`, `publish`, `poll`, and `subscribe` helper methods are used"
              },
              {
                "id": "channels_types_declared",
                "text": "every used channel and event type is declared"
              },
              {
                "id": "bounded_limits",
                "text": "each channel has bounded retention, event count, and payload size within the exact platform limits"
              },
              {
                "id": "app_user_dependency",
                "text": "`app_user` channels also declare enabled `app_users@1`"
              },
              {
                "id": "no_client_authority",
                "text": "no client-supplied app/user/subject/session/storage identifier is used as authorization authority"
              },
              {
                "id": "durable_data_separate",
                "text": "durable business records remain in `app_database@1` or another appropriate durable capability"
              },
              {
                "id": "cursor_reset_refreshes",
                "text": "cursor reset causes an authoritative state refresh instead of guessing missing events"
              },
              {
                "id": "bounded_subscribe_retry",
                "text": "subscribe retry uses a bounded exponential backoff with a single in-flight poll"
              },
              {
                "id": "no_reconnect_amplification",
                "text": "reconnect preserves the cursor and does not republish replay/presence events automatically"
              },
              {
                "id": "presence_ephemeral",
                "text": "presence is treated only as an ephemeral hint"
              },
              {
                "id": "no_sensitive_payloads",
                "text": "realtime payloads contain no secrets, credentials, raw session tokens, files, or large/private record bodies"
              }
            ]
          }
        },
        {
          "instructionModuleId": "aqteron.capability.web_parser@1",
          "moduleKey": "aqteron.capability.web_parser@1",
          "moduleKind": "capability",
          "sourcePath": "capabilities/WEB_PARSER.md",
          "instructionModuleVersionId": "aqteron.capability.web_parser@1@0.1.4",
          "versionLabel": "0.1.4",
          "contentSha256": "3360d11b8d7fd6124694cd83d606eccb68bafe2f697dba915fa655f12c36661a",
          "status": "draft",
          "contract": "Aqteron PWA v1",
          "selectionMetadata": {
            "schemaVersion": "aqteron.builder.selection_metadata.v1",
            "summary": "Bounded readable-text parsing for explicitly approved public domains.",
            "userNeeds": [
              "read sanitized text from approved public HTTP(S) pages",
              "extract readable text from a specific public URL",
              "use public web text inside an Aqteron workflow"
            ],
            "selectionSignals": [
              "live generation context marks this module usable for the account",
              "source pages are public, readable, and approved",
              "readable_text output is sufficient"
            ],
            "exclusions": [
              "login-only, private, internal, localhost, or metadata URLs",
              "broad crawling, screenshots, binary downloads, raw HTML execution, or browser automation"
            ],
            "dependencies": [],
            "compatibility": {
              "contracts": [
                "Aqteron PWA v1"
              ],
              "requires": [],
              "conflicts": []
            },
            "runtime": {
              "adapterId": "web_parser@1"
            },
            "availability": {
              "instructionStatus": "draft",
              "registryStatus": "available",
              "runtimeStatus": "runtime_available",
              "builderSelectable": true,
              "instructionVisible": true,
              "entitlementAuthority": "aqteron_validator_runtime",
              "notSelectableReason": null
            }
          },
          "capabilityAvailability": {
            "capabilityKey": "web_parser@1",
            "registryStatus": "available",
            "runtimeStatus": "runtime_available",
            "builderSelectable": true,
            "instructionVisible": true,
            "entitlementAuthority": "aqteron_validator_runtime"
          },
          "selfCheckMetadata": {
            "schemaVersion": "aqteron.builder.module_self_check.v1",
            "instructionModuleId": "aqteron.capability.web_parser@1",
            "moduleKind": "capability",
            "required": true,
            "appliesWhenSelected": true,
            "sourceHeading": "Module self-check",
            "checks": [
              {
                "id": "workflow_needs_public_text",
                "text": "the user workflow genuinely needs public readable text"
              },
              {
                "id": "requested_domains_declared",
                "text": "every requested domain is explicitly declared"
              },
              {
                "id": "readable_text_only",
                "text": "only `readable_text` is requested"
              },
              {
                "id": "no_login_or_auth_forwarding",
                "text": "no login/session/cookie/Auth forwarding is attempted"
              },
              {
                "id": "no_private_targets",
                "text": "no private/internal/localhost/IP target is accepted"
              },
              {
                "id": "no_direct_scraping",
                "text": "no direct cross-origin scraping/headless crawling is implemented"
              },
              {
                "id": "declaration_request_agree",
                "text": "capability declaration and request URL agree"
              },
              {
                "id": "platform_errors_user_facing",
                "text": "platform errors are shown in user-facing form"
              }
            ]
          }
        },
        {
          "instructionModuleId": "aqteron.capability.webrtc_signaling@1",
          "moduleKey": "aqteron.capability.webrtc_signaling@1",
          "moduleKind": "capability",
          "sourcePath": "capabilities/WEBRTC_SIGNALING.md",
          "instructionModuleVersionId": "aqteron.capability.webrtc_signaling@1@0.1.6",
          "versionLabel": "0.1.6",
          "contentSha256": "69d9a7cd353062540860ed9893da8d662f36a0887771d5008b66611a21f3edc0",
          "status": "draft",
          "contract": "Aqteron PWA v1",
          "selectionMetadata": {
            "schemaVersion": "aqteron.builder.selection_metadata.v1",
            "summary": "Short-lived app-scoped signaling for browser peer-to-peer WebRTC setup.",
            "userNeeds": [
              "coordinate browser peer-to-peer audio, video, or data channel setup",
              "exchange short-lived WebRTC signaling messages",
              "support real-time peer connection workflows"
            ],
            "selectionSignals": [
              "live generation context marks this module usable for the account",
              "application needs WebRTC signaling with platform-managed relay fallback when direct connectivity fails",
              "short-lived helper-mediated signaling and managed ICE credentials are sufficient"
            ],
            "exclusions": [
              "media recording, SFU/media processing, custom TURN/STUN credential management, or persistent chat storage",
              "storing SDP or ICE payloads in app_database@1"
            ],
            "dependencies": [],
            "compatibility": {
              "contracts": [
                "Aqteron PWA v1"
              ],
              "requires": [],
              "conflicts": []
            },
            "runtime": {
              "adapterId": "webrtc_signaling@1"
            },
            "availability": {
              "instructionStatus": "draft",
              "registryStatus": "available",
              "runtimeStatus": "runtime_available",
              "builderSelectable": true,
              "instructionVisible": true,
              "entitlementAuthority": "aqteron_validator_runtime",
              "notSelectableReason": null
            }
          },
          "capabilityAvailability": {
            "capabilityKey": "webrtc_signaling@1",
            "registryStatus": "available",
            "runtimeStatus": "runtime_available",
            "builderSelectable": true,
            "instructionVisible": true,
            "entitlementAuthority": "aqteron_validator_runtime"
          },
          "selfCheckMetadata": {
            "schemaVersion": "aqteron.builder.module_self_check.v1",
            "instructionModuleId": "aqteron.capability.webrtc_signaling@1",
            "moduleKind": "capability",
            "required": true,
            "appliesWhenSelected": true,
            "sourceHeading": "Module self-check",
            "checks": [
              {
                "id": "declared_when_helper_used",
                "text": "the capability is declared if signaling helper is used"
              },
              {
                "id": "signaling_not_database_persisted",
                "text": "signaling data is not persisted in `app_database@1`"
              },
              {
                "id": "no_custom_signaling_route",
                "text": "no private/custom signaling server route is invented"
              },
              {
                "id": "bounded_payload_and_ttl",
                "text": "payload size and TTL are bounded"
              },
              {
                "id": "managed_turn_media_boundary",
                "text": "media remains browser WebRTC traffic; managed TURN is only an encrypted-packet relay and is not recording or media processing"
              },
              {
                "id": "managed_turn_helper_only",
                "text": "ICE configuration comes only from the platform helper; no hardcoded relay credentials or routes are embedded"
              },
              {
                "id": "managed_turn_ephemeral",
                "text": "short-lived managed TURN credentials are never persisted and are refreshed for new/recovered calls"
              },
              {
                "id": "participant_resume_bounded",
                "text": "participant recovery uses only the server-issued volatile `resumeToken` and bounded `participant.resume` retries"
              },
              {
                "id": "app_user_resume_continuity",
                "text": "app-user-bound participants cannot resume as a different trusted app user"
              },
              {
                "id": "no_blind_signal_retry",
                "text": "non-idempotent signaling sends are not blindly retried"
              },
              {
                "id": "recovery_cursor_continuity",
                "text": "recovery continues from the last signaling sequence rather than replaying from zero"
              },
              {
                "id": "visible_failure_states",
                "text": "call failure and unsupported-environment states are shown to the user"
              }
            ]
          }
        },
        {
          "instructionModuleId": "aqteron.final-check.pwa-v1",
          "moduleKey": "aqteron.final-check.pwa-v1",
          "moduleKind": "final_check",
          "sourcePath": "FINAL_CHECK.md",
          "instructionModuleVersionId": "aqteron.final-check.pwa-v1@0.2.2",
          "versionLabel": "0.2.2",
          "contentSha256": "0d6797c3c4324694a36e8e9f61e8f4c7351ed97a4ea683e1455df23d58598d77",
          "status": "draft",
          "contract": "Aqteron PWA v1",
          "selectionMetadata": null,
          "capabilityAvailability": null,
          "selfCheckMetadata": null
        },
        {
          "instructionModuleId": "aqteron.final-response.user-facing-v1",
          "moduleKey": "aqteron.final-response.user-facing-v1",
          "moduleKind": "final_response",
          "sourcePath": "FINAL_RESPONSE.md",
          "instructionModuleVersionId": "aqteron.final-response.user-facing-v1@0.1.1",
          "versionLabel": "0.1.1",
          "contentSha256": "9784bf20ba0c313a559375b12d7fe83c921ae7ef8122cbf448b008a79a93d31a",
          "status": "draft",
          "contract": "Aqteron PWA v1",
          "selectionMetadata": null,
          "capabilityAvailability": null,
          "selfCheckMetadata": null
        },
        {
          "instructionModuleId": "aqteron.package.pwa-v1",
          "moduleKey": "aqteron.package.pwa-v1",
          "moduleKind": "package",
          "sourcePath": "PACKAGE.md",
          "instructionModuleVersionId": "aqteron.package.pwa-v1@0.1.3",
          "versionLabel": "0.1.3",
          "contentSha256": "8fdd25c656a7dd2a171660eb7bbb419bebf0835b72b00c10158f06660abe16f1",
          "status": "draft",
          "contract": "Aqteron PWA v1",
          "selectionMetadata": null,
          "capabilityAvailability": null,
          "selfCheckMetadata": null
        },
        {
          "instructionModuleId": "aqteron.type.app",
          "moduleKey": "aqteron.type.app",
          "moduleKind": "type",
          "sourcePath": "types/APP.md",
          "instructionModuleVersionId": "aqteron.type.app@0.1.1",
          "versionLabel": "0.1.1",
          "contentSha256": "a4d220de4a687403f00c74f3a2658885f035c400b3bbb5bd869c9b074b75ca03",
          "status": "draft",
          "contract": "Aqteron PWA v1",
          "selectionMetadata": {
            "schemaVersion": "aqteron.builder.selection_metadata.v1",
            "summary": "Focused record or workflow application for repeated personal or business tasks.",
            "userNeeds": [
              "track records or ongoing state",
              "organize repeated workflows",
              "manage personal or business data"
            ],
            "selectionSignals": [
              "records need create/view/edit/delete behavior",
              "workflow spans multiple steps or screens",
              "saved state is central to the user value"
            ],
            "exclusions": [
              "one-off calculator, converter, validator, or generator",
              "primarily informational or promotional website",
              "playable game-first request"
            ],
            "dependencies": [],
            "compatibility": {
              "contracts": [
                "Aqteron PWA v1"
              ],
              "requires": [],
              "conflicts": []
            },
            "runtime": {
              "adapterId": null
            },
            "availability": {
              "instructionStatus": "draft",
              "registryStatus": null,
              "runtimeStatus": null,
              "builderSelectable": true,
              "instructionVisible": true,
              "entitlementAuthority": null,
              "notSelectableReason": null
            }
          },
          "capabilityAvailability": null,
          "selfCheckMetadata": null
        },
        {
          "instructionModuleId": "aqteron.type.game",
          "moduleKey": "aqteron.type.game",
          "moduleKind": "type",
          "sourcePath": "types/GAME.md",
          "instructionModuleVersionId": "aqteron.type.game@0.1.1",
          "versionLabel": "0.1.1",
          "contentSha256": "fad98ade2dfb39851e044dc3c461982c3991481aa99304a24e84309d036fff8f",
          "status": "draft",
          "contract": "Aqteron PWA v1",
          "selectionMetadata": {
            "schemaVersion": "aqteron.builder.selection_metadata.v1",
            "summary": "Playable browser game with a complete objective, loop, controls, and feedback.",
            "userNeeds": [
              "play a browser game",
              "support scoring, levels, turns, challenge, or replay",
              "create an interactive entertainment experience"
            ],
            "selectionSignals": [
              "primary value is gameplay",
              "rules, controls, win/loss, score, or progression are required",
              "first screen should start or explain play"
            ],
            "exclusions": [
              "business or personal record workflow",
              "one-off productivity utility",
              "informational or promotional website"
            ],
            "dependencies": [],
            "compatibility": {
              "contracts": [
                "Aqteron PWA v1"
              ],
              "requires": [],
              "conflicts": []
            },
            "runtime": {
              "adapterId": null
            },
            "availability": {
              "instructionStatus": "draft",
              "registryStatus": null,
              "runtimeStatus": null,
              "builderSelectable": true,
              "instructionVisible": true,
              "entitlementAuthority": null,
              "notSelectableReason": null
            }
          },
          "capabilityAvailability": null,
          "selfCheckMetadata": null
        },
        {
          "instructionModuleId": "aqteron.type.tool",
          "moduleKey": "aqteron.type.tool",
          "moduleKind": "type",
          "sourcePath": "types/TOOL.md",
          "instructionModuleVersionId": "aqteron.type.tool@0.1.1",
          "versionLabel": "0.1.1",
          "contentSha256": "542e780b53c5b6cbcff55fa71d3b8661d0089364b5e1a2359a6640b62da3f008",
          "status": "draft",
          "contract": "Aqteron PWA v1",
          "selectionMetadata": {
            "schemaVersion": "aqteron.builder.selection_metadata.v1",
            "summary": "Direct task-first utility for a narrow input-action-result workflow.",
            "userNeeds": [
              "calculate, convert, generate, analyze, validate, format, or plan",
              "complete a narrow task with clear inputs and outputs",
              "reuse a compact work instrument"
            ],
            "selectionSignals": [
              "single primary action produces the result",
              "inputs, assumptions, validation, and output are the main workflow",
              "dashboard, account, or record lifecycle is not central"
            ],
            "exclusions": [
              "broad multi-record application",
              "marketing or content website",
              "playable game"
            ],
            "dependencies": [],
            "compatibility": {
              "contracts": [
                "Aqteron PWA v1"
              ],
              "requires": [],
              "conflicts": []
            },
            "runtime": {
              "adapterId": null
            },
            "availability": {
              "instructionStatus": "draft",
              "registryStatus": null,
              "runtimeStatus": null,
              "builderSelectable": true,
              "instructionVisible": true,
              "entitlementAuthority": null,
              "notSelectableReason": null
            }
          },
          "capabilityAvailability": null,
          "selfCheckMetadata": null
        },
        {
          "instructionModuleId": "aqteron.type.website",
          "moduleKey": "aqteron.type.website",
          "moduleKind": "type",
          "sourcePath": "types/WEBSITE.md",
          "instructionModuleVersionId": "aqteron.type.website@0.1.1",
          "versionLabel": "0.1.1",
          "contentSha256": "278a6fed8766375fe579f692438e7d0c88d44b192f09caff734a5fcd3e580c5c",
          "status": "draft",
          "contract": "Aqteron PWA v1",
          "selectionMetadata": {
            "schemaVersion": "aqteron.builder.selection_metadata.v1",
            "summary": "Publishable informational, promotional, portfolio, catalogue, or company website.",
            "userNeeds": [
              "present information, brand, offer, work, catalogue, or content",
              "guide visitors to contact, buy, book, learn, or explore",
              "publish a multi-section or multi-page site"
            ],
            "selectionSignals": [
              "visitor communication is the main goal",
              "sections such as overview, proof, services, pricing, FAQ, or contact are useful",
              "content hierarchy and calls to action matter more than record management"
            ],
            "exclusions": [
              "repeated record-based application",
              "single-purpose calculator or generator",
              "playable game"
            ],
            "dependencies": [],
            "compatibility": {
              "contracts": [
                "Aqteron PWA v1"
              ],
              "requires": [],
              "conflicts": []
            },
            "runtime": {
              "adapterId": null
            },
            "availability": {
              "instructionStatus": "draft",
              "registryStatus": null,
              "runtimeStatus": null,
              "builderSelectable": true,
              "instructionVisible": true,
              "entitlementAuthority": null,
              "notSelectableReason": null
            }
          },
          "capabilityAvailability": null,
          "selfCheckMetadata": null
        }
      ],
      "capabilityRegistry": [
        {
          "capabilityKey": "ai_bridge@1",
          "instructionModuleId": null,
          "instructionModuleVersionId": null,
          "registryStatus": "disabled",
          "displayName": "AI Bridge",
          "summary": "Disabled scaffold capability; unavailable in current production.",
          "metadata": {
            "runtimeStatus": "disabled_scaffold",
            "builderSelectable": false,
            "instructionVisible": false,
            "entitlementAuthority": "aqteron_validator_runtime",
            "presentation": {
              "locales": {
                "en": {
                  "name": "AI Bridge",
                  "summary": "Disabled scaffold capability; unavailable in current production."
                },
                "fr": {
                  "name": "Passerelle IA",
                  "summary": "Capacité préparatoire désactivée, indisponible dans la production actuelle."
                },
                "ru": {
                  "name": "Шлюз ИИ",
                  "summary": "Отключённая заготовка возможности; недоступна в текущей production-среде."
                }
              }
            },
            "notSelectableReason": "Disabled scaffold capability; unavailable in current production."
          },
          "createdAt": "2026-09-16T05:00:00.000Z",
          "updatedAt": "2026-09-16T05:00:00.000Z"
        },
        {
          "capabilityKey": "app_database@1",
          "instructionModuleId": "aqteron.capability.app_database@1",
          "instructionModuleVersionId": "aqteron.capability.app_database@1@0.1.5",
          "registryStatus": "available",
          "displayName": "App Database",
          "summary": "App-scoped JSON record storage for shared or cross-device persistence.",
          "metadata": {
            "runtimeStatus": "runtime_available",
            "builderSelectable": true,
            "instructionVisible": true,
            "entitlementAuthority": "aqteron_validator_runtime",
            "presentation": {
              "locales": {
                "en": {
                  "name": "App Database",
                  "summary": "App-scoped JSON record storage for shared or cross-device persistence."
                },
                "fr": {
                  "name": "Base de données de l'application",
                  "summary": "Stockage de documents JSON propre à l'application pour une persistance partagée ou multi-appareil."
                },
                "ru": {
                  "name": "База данных приложения",
                  "summary": "Хранилище JSON-записей приложения для общего доступа и синхронизации между устройствами."
                }
              }
            },
            "sourcePath": "capabilities/APP_DATABASE.md",
            "selectionMetadata": {
              "schemaVersion": "aqteron.builder.selection_metadata.v1",
              "summary": "App-scoped JSON record storage for shared or cross-device persistence.",
              "userNeeds": [
                "persist structured records beyond one browser or install",
                "share app-scoped records across linked users or devices",
                "store bounded server-side JSON records"
              ],
              "selectionSignals": [
                "localStorage or IndexedDB is insufficient",
                "records must survive reinstall or device changes",
                "multiple users or devices need the same app data"
              ],
              "exclusions": [
                "file, image, document, or attachment storage",
                "raw SQL or arbitrary backend database access",
                "secrets, credentials, passwords, tokens, or private keys"
              ],
              "dependencies": [],
              "compatibility": {
                "contracts": [
                  "Aqteron PWA v1"
                ],
                "requires": [],
                "conflicts": []
              },
              "runtime": {
                "adapterId": "app_database@1"
              },
              "availability": {
                "instructionStatus": "draft",
                "registryStatus": "available",
                "runtimeStatus": "runtime_available",
                "builderSelectable": true,
                "instructionVisible": true,
                "entitlementAuthority": "aqteron_validator_runtime",
                "notSelectableReason": null
              }
            },
            "selfCheckMetadata": {
              "schemaVersion": "aqteron.builder.module_self_check.v1",
              "instructionModuleId": "aqteron.capability.app_database@1",
              "moduleKind": "capability",
              "required": true,
              "appliesWhenSelected": true,
              "sourceHeading": "Module self-check",
              "checks": [
                {
                  "id": "declared_when_helper_used",
                  "text": "capability is declared when JavaScript uses `appDatabase`"
                },
                {
                  "id": "used_collections_declared",
                  "text": "every used collection is declared"
                },
                {
                  "id": "schema_keys_match",
                  "text": "schema and JS keys are identical lower_snake_case ASCII"
                },
                {
                  "id": "no_undeclared_fields",
                  "text": "no undeclared extra fields are written"
                },
                {
                  "id": "new_record_uses_put",
                  "text": "every new logical record uses `put` with declared `record.create`"
                },
                {
                  "id": "existing_record_uses_set",
                  "text": "every existing logical record update uses `set` with declared `record.update`"
                },
                {
                  "id": "offline_replay_preserves_intent",
                  "text": "offline/deferred replay preserves `put` versus `set` operation intent"
                },
                {
                  "id": "bounded_list_limit",
                  "text": "every `list` call has an explicit numeric limit from 1 to 100"
                },
                {
                  "id": "db_list_limit_not_record_quota",
                  "text": "a `list` retrieval limit is not treated as the collection `maxRecords` quota"
                },
                {
                  "id": "no_raw_secrets",
                  "text": "no raw secrets are persisted"
                },
                {
                  "id": "no_private_database_routes",
                  "text": "no direct/private database routes or raw SQL are used"
                },
                {
                  "id": "app_user_server_authority",
                  "text": "when `authMode: \"app_user\"` is selected, `app_users@1` is enabled and authorization comes only from the trusted server-resolved app-user session"
                },
                {
                  "id": "no_client_identity_or_row_privacy_claim",
                  "text": "no client-supplied user identity is treated as authority and no row-level privacy is claimed from `authMode` alone"
                },
                {
                  "id": "user_readable_errors",
                  "text": "capability failures produce user-readable UI errors"
                }
              ]
            }
          },
          "createdAt": "2026-09-16T05:00:00.000Z",
          "updatedAt": "2026-09-21T05:10:00.000Z"
        },
        {
          "capabilityKey": "app_files@1",
          "instructionModuleId": "aqteron.capability.app_files@1",
          "instructionModuleVersionId": "aqteron.capability.app_files@1@0.3.1",
          "registryStatus": "available",
          "displayName": "App Files",
          "summary": "Guarded private file storage for entitled applications when canonical readiness controls pass.",
          "metadata": {
            "runtimeStatus": "runtime_available",
            "builderSelectable": true,
            "instructionVisible": true,
            "entitlementAuthority": "aqteron_validator_runtime",
            "presentation": {
              "locales": {
                "en": {
                  "name": "App Files",
                  "summary": "Guarded private file storage for entitled applications when canonical readiness controls pass."
                },
                "fr": {
                  "name": "Fichiers de l'application",
                  "summary": "Stockage de fichiers privés protégé pour les applications autorisées lorsque les contrôles de disponibilité canoniques réussissent."
                },
                "ru": {
                  "name": "Файлы приложения",
                  "summary": "Защищённое приватное хранилище файлов для приложений с правом доступа при успешной канонической проверке готовности."
                }
              }
            },
            "sourcePath": "capabilities/APP_FILES.md",
            "selectionMetadata": {
              "schemaVersion": "aqteron.builder.selection_metadata.v1",
              "summary": "Guarded private file storage for entitled applications when canonical readiness controls pass.",
              "userNeeds": [
                "store user files, attachments, images, documents, imports, or exports",
                "keep private application-scoped files in managed storage",
                "associate files with app workflows"
              ],
              "selectionSignals": [
                "managed private files are required and server-side entitlement is available",
                "files must persist outside local browser storage",
                "workflow references uploaded or generated files"
              ],
              "exclusions": [
                "workflows that can remain entirely in local browser storage",
                "public hosting or public URL generation",
                "shared-drive behavior across unrelated apps or users",
                "structured JSON record storage without files"
              ],
              "dependencies": [],
              "compatibility": {
                "contracts": [
                  "Aqteron PWA v1"
                ],
                "requires": [],
                "conflicts": []
              },
              "runtime": {
                "adapterId": "app_files@1"
              },
              "availability": {
                "instructionStatus": "activation_candidate",
                "registryStatus": "available",
                "runtimeStatus": "runtime_available",
                "builderSelectable": true,
                "instructionVisible": true,
                "entitlementAuthority": "aqteron_validator_runtime",
                "notSelectableReason": null
              }
            },
            "selfCheckMetadata": {
              "schemaVersion": "aqteron.builder.module_self_check.v1",
              "instructionModuleId": "aqteron.capability.app_files@1",
              "moduleKind": "capability",
              "required": true,
              "appliesWhenSelected": true,
              "sourceHeading": "Module self-check",
              "checks": [
                {
                  "id": "declared_when_helper_used",
                  "text": "capability is declared if `appFiles` is used"
                },
                {
                  "id": "only_prompt2app_helper",
                  "text": "only the exact `window.Prompt2App.appFiles` methods above are used"
                },
                {
                  "id": "subject_mode_identity_matches",
                  "text": "identity handling matches the declared subject mode: `app_user` requires trusted app-local sign-in, `app` does not account-link, and only legacy no-`subjectMode` declarations may call `connectAccount()`"
                },
                {
                  "id": "no_client_file_identity_authority",
                  "text": "no client-provided user/subject identifier is used as file authorization authority"
                },
                {
                  "id": "used_buckets_declared_private",
                  "text": "every used bucket is declared and private"
                },
                {
                  "id": "file_quota_dimensions_coherent",
                  "text": "MIME types are bounded and `maxFileSizeBytes`, `maxTotalBytes`, and `maxFiles` are validated as separate dimensions within their exact ceilings"
                },
                {
                  "id": "mixed_db_files_fixture_coherent",
                  "text": "mixed database/file workflows keep database `list` limits, database `maxRecords`, and file `maxFiles` distinct and dimensionally coherent"
                },
                {
                  "id": "exact_file_transport",
                  "text": "file inputs are browser `File` values and downloads use `contentBase64`"
                },
                {
                  "id": "no_invented_storage_authority",
                  "text": "no public/presigned/storage URLs, filesystem paths, internal metadata, or unsupported sharing are invented"
                },
                {
                  "id": "server_entitlement_authority",
                  "text": "server entitlement is never inferred from the package"
                },
                {
                  "id": "visible_errors",
                  "text": "errors are visible and do not falsely report successful storage"
                }
              ]
            }
          },
          "createdAt": "2026-09-16T05:00:00.000Z",
          "updatedAt": "2026-09-21T05:10:00.000Z"
        },
        {
          "capabilityKey": "app_jobs@1",
          "instructionModuleId": "aqteron.capability.app_jobs@1",
          "instructionModuleVersionId": "aqteron.capability.app_jobs@1@0.1.0",
          "registryStatus": "available",
          "displayName": "App Jobs",
          "summary": "Bounded delayed and retryable external API actions executed by a managed worker.",
          "metadata": {
            "runtimeStatus": "runtime_available",
            "builderSelectable": true,
            "instructionVisible": true,
            "entitlementAuthority": "aqteron_validator_runtime",
            "presentation": {
              "locales": {
                "en": {
                  "name": "App Jobs",
                  "summary": "Bounded delayed and retryable external API actions executed by a managed worker."
                },
                "fr": {
                  "name": "Tâches de l'application",
                  "summary": "Actions d’API externe différées et réessayables, limitées et exécutées par un worker géré."
                },
                "ru": {
                  "name": "Задачи приложения",
                  "summary": "Ограниченные отложенные и повторяемые вызовы внешнего API через управляемый воркер."
                }
              }
            },
            "sourcePath": "capabilities/APP_JOBS.md",
            "selectionMetadata": {
              "schemaVersion": "aqteron.builder.selection_metadata.v1",
              "summary": "Bounded delayed and retryable external API actions executed by a managed worker.",
              "userNeeds": [
                "run an approved external API action later",
                "retry transient external API failures with bounded backoff",
                "inspect and cancel pending managed jobs"
              ],
              "selectionSignals": [
                "the scheduled work is representable as an external_api_proxy request descriptor",
                "one-time delayed execution and bounded retries are sufficient"
              ],
              "exclusions": [
                "arbitrary code execution, cron scripts, unbounded recurring tasks, raw secrets in payloads, or custom background servers"
              ],
              "dependencies": [
                "external_api_proxy@1",
                "app_secrets@1"
              ],
              "compatibility": {
                "contracts": [
                  "Aqteron PWA v1"
                ],
                "requires": [
                  "external_api_proxy@1",
                  "app_secrets@1"
                ],
                "conflicts": []
              },
              "runtime": {
                "adapterId": "app_jobs@1"
              },
              "availability": {
                "instructionStatus": "draft",
                "registryStatus": "available",
                "runtimeStatus": "runtime_available",
                "builderSelectable": true,
                "instructionVisible": true,
                "entitlementAuthority": "aqteron_validator_runtime",
                "notSelectableReason": null
              }
            },
            "selfCheckMetadata": {
              "schemaVersion": "aqteron.builder.module_self_check.v1",
              "instructionModuleId": "aqteron.capability.app_jobs@1",
              "moduleKind": "capability",
              "required": true,
              "appliesWhenSelected": true,
              "sourceHeading": "Module self-check",
              "checks": [
                {
                  "id": "dependencies_declared",
                  "text": "`external_api_proxy@1` and required `app_secrets@1` references are declared"
                },
                {
                  "id": "request_allowlisted",
                  "text": "every scheduled request satisfies the declared external API domain and method allowlist"
                },
                {
                  "id": "bounded_schedule",
                  "text": "run time, queue size, retry count, and retry delay stay inside declared bounds"
                },
                {
                  "id": "idempotency_key",
                  "text": "each logical scheduled action uses a stable non-secret idempotency key"
                },
                {
                  "id": "no_raw_credentials",
                  "text": "scheduled job payloads contain no raw credentials or arbitrary backend code"
                },
                {
                  "id": "app_user_dependency",
                  "text": "`authMode: \"app_user\"` also declares enabled `app_users@1`"
                },
                {
                  "id": "managed_helper_only",
                  "text": "generated code uses only the managed job status/schedule/list/get/cancel helpers"
                }
              ]
            }
          },
          "createdAt": "2026-09-21T10:50:00.000Z",
          "updatedAt": "2026-09-21T10:50:00.000Z"
        },
        {
          "capabilityKey": "app_secrets@1",
          "instructionModuleId": "aqteron.capability.app_secrets@1",
          "instructionModuleVersionId": "aqteron.capability.app_secrets@1@0.1.0",
          "registryStatus": "available",
          "displayName": "App Secrets",
          "summary": "Server-held encrypted credential references that are never exposed to generated app JavaScript.",
          "metadata": {
            "runtimeStatus": "runtime_available",
            "builderSelectable": true,
            "instructionVisible": true,
            "entitlementAuthority": "aqteron_validator_runtime",
            "presentation": {
              "locales": {
                "en": {
                  "name": "App Secrets",
                  "summary": "Server-held encrypted credential references that are never exposed to generated app JavaScript."
                },
                "fr": {
                  "name": "Secrets de l'application",
                  "summary": "Références d’identifiants chiffrées conservées côté serveur et jamais exposées au JavaScript de l’application."
                },
                "ru": {
                  "name": "Секреты приложения",
                  "summary": "Зашифрованные серверные ссылки на учётные данные без передачи исходных значений JavaScript приложения."
                }
              }
            },
            "sourcePath": "capabilities/APP_SECRETS.md",
            "selectionMetadata": {
              "schemaVersion": "aqteron.builder.selection_metadata.v1",
              "summary": "Server-held encrypted credential references that are never exposed to generated app JavaScript.",
              "userNeeds": [
                "store third-party API credentials without exposing them to browser code",
                "let the app owner configure named server-held credential references",
                "rotate or revoke integration credentials without rebuilding the application"
              ],
              "selectionSignals": [
                "an external integration needs an API key, token, or signing secret",
                "the credential must remain server-side",
                "the user can configure the credential after publication"
              ],
              "exclusions": [
                "embedding raw credentials in ZIP files, metadata, JavaScript, browser storage, logs, or job payloads",
                "using app_secrets as general user data storage"
              ],
              "dependencies": [],
              "compatibility": {
                "contracts": [
                  "Aqteron PWA v1"
                ],
                "requires": [],
                "conflicts": []
              },
              "runtime": {
                "adapterId": "app_secrets@1"
              },
              "availability": {
                "instructionStatus": "draft",
                "registryStatus": "available",
                "runtimeStatus": "runtime_available",
                "builderSelectable": true,
                "instructionVisible": true,
                "entitlementAuthority": "aqteron_validator_runtime",
                "notSelectableReason": null
              }
            },
            "selfCheckMetadata": {
              "schemaVersion": "aqteron.builder.module_self_check.v1",
              "instructionModuleId": "aqteron.capability.app_secrets@1",
              "moduleKind": "capability",
              "required": true,
              "appliesWhenSelected": true,
              "sourceHeading": "Module self-check",
              "checks": [
                {
                  "id": "declared_when_needed",
                  "text": "`app_secrets@1` is declared whenever server-held integration credentials are required"
                },
                {
                  "id": "refs_declared",
                  "text": "every credential reference used by another capability is declared in `config.refs`"
                },
                {
                  "id": "no_raw_secret_in_package",
                  "text": "no raw secret value appears in ZIP files, metadata, JavaScript, browser storage, logs, webhook payloads, or job payloads"
                },
                {
                  "id": "status_only_browser",
                  "text": "generated app code uses only status visibility and never expects a raw secret value"
                },
                {
                  "id": "owner_configuration",
                  "text": "the user-facing flow explains that the application owner configures the credential in Aqteron"
                },
                {
                  "id": "rotation_safe",
                  "text": "rotation or revocation does not require rebuilding the generated application"
                }
              ]
            }
          },
          "createdAt": "2026-09-21T10:50:00.000Z",
          "updatedAt": "2026-09-21T10:50:00.000Z"
        },
        {
          "capabilityKey": "app_users@1",
          "instructionModuleId": "aqteron.capability.app_users@1",
          "instructionModuleVersionId": "aqteron.capability.app_users@1@0.1.1",
          "registryStatus": "available",
          "displayName": "App Users",
          "summary": "Isolated application-local user accounts, sessions, roles, permissions, and credential recovery.",
          "metadata": {
            "runtimeStatus": "runtime_available",
            "builderSelectable": true,
            "instructionVisible": true,
            "entitlementAuthority": "aqteron_validator_runtime",
            "presentation": {
              "locales": {
                "en": {
                  "name": "App Users",
                  "summary": "Isolated application-local user accounts, sessions, roles, permissions, and credential recovery."
                },
                "fr": {
                  "name": "Utilisateurs de l'application",
                  "summary": "Comptes, sessions, rôles, autorisations et récupération d’identifiants isolés pour chaque application."
                },
                "ru": {
                  "name": "Пользователи приложения",
                  "summary": "Изолированные локальные аккаунты приложения, сессии, роли, права и восстановление учётных данных."
                }
              }
            },
            "sourcePath": "capabilities/APP_USERS.md",
            "selectionMetadata": {
              "schemaVersion": "aqteron.builder.selection_metadata.v1",
              "summary": "Isolated application-local user accounts, sessions, roles, permissions, and credential recovery.",
              "userNeeds": [
                "let visitors create or use accounts that belong only to the application",
                "maintain application-local sign-in sessions across visits",
                "check application-local roles or permissions"
              ],
              "selectionSignals": [
                "the requested workflow needs sign-in that must not depend on Aqteron platform accounts",
                "multiple end users need distinct identities inside one published application",
                "managed credential hashing, lockout, recovery, or session revocation is required"
              ],
              "exclusions": [
                "Aqteron platform account authentication or account linking",
                "custom authentication servers or direct credential storage",
                "workflows that need no user identity"
              ],
              "dependencies": [],
              "compatibility": {
                "contracts": [
                  "Aqteron PWA v1"
                ],
                "requires": [],
                "conflicts": []
              },
              "runtime": {
                "adapterId": "app_users@1"
              },
              "availability": {
                "instructionStatus": "draft",
                "registryStatus": "available",
                "runtimeStatus": "runtime_available",
                "builderSelectable": true,
                "instructionVisible": true,
                "entitlementAuthority": "aqteron_validator_runtime",
                "notSelectableReason": null
              }
            },
            "selfCheckMetadata": {
              "schemaVersion": "aqteron.builder.module_self_check.v1",
              "instructionModuleId": "aqteron.capability.app_users@1",
              "moduleKind": "capability",
              "required": true,
              "appliesWhenSelected": true,
              "sourceHeading": "Module self-check",
              "checks": [
                {
                  "id": "declared_when_helper_used",
                  "text": "`app_users@1` is declared whenever `appUsers` is used"
                },
                {
                  "id": "supported_methods_only",
                  "text": "only the exact `window.Prompt2App.appUsers` public methods above are used"
                },
                {
                  "id": "platform_identity_separate",
                  "text": "app users are never treated as Aqteron platform accounts"
                },
                {
                  "id": "no_custom_auth_backend",
                  "text": "no custom authentication backend or private app-user route is invented"
                },
                {
                  "id": "no_raw_auth_secrets",
                  "text": "raw passwords, PINs, recovery codes, session tokens, and cookies are never persisted by generated code"
                },
                {
                  "id": "registration_mode_matches",
                  "text": "registration UI matches the declared `registrationMode`"
                },
                {
                  "id": "bounded_security_policy",
                  "text": "credential types and session/lockout bounds match the declaration contract"
                },
                {
                  "id": "permission_boundary",
                  "text": "permission checks do not rely on hiding UI as server authorization"
                },
                {
                  "id": "admin_ops_not_public",
                  "text": "role assignment and recovery-code issuance are not exposed as public browser operations"
                },
                {
                  "id": "trusted_cross_capability_authority",
                  "text": "capability combinations that require app-user authority derive it only from the trusted server session and never from client-selected user IDs"
                },
                {
                  "id": "current_binding_modes",
                  "text": "per-user files use `subjectMode: \"app_user\"`, database sign-in gates use `authMode: \"app_user\"`, and push does not account-link when `app_users@1` is enabled"
                },
                {
                  "id": "visible_auth_states",
                  "text": "authentication, lockout, recovery, and unavailable states are shown clearly to the user"
                }
              ]
            }
          },
          "createdAt": "2026-09-16T05:00:00.000Z",
          "updatedAt": "2026-09-21T05:10:00.000Z"
        },
        {
          "capabilityKey": "app_webhooks@1",
          "instructionModuleId": "aqteron.capability.app_webhooks@1",
          "instructionModuleVersionId": "aqteron.capability.app_webhooks@1@0.1.0",
          "registryStatus": "available",
          "displayName": "App Webhooks",
          "summary": "Verified bounded inbound JSON webhook events isolated per Application Environment.",
          "metadata": {
            "runtimeStatus": "runtime_available",
            "builderSelectable": true,
            "instructionVisible": true,
            "entitlementAuthority": "aqteron_validator_runtime",
            "presentation": {
              "locales": {
                "en": {
                  "name": "App Webhooks",
                  "summary": "Verified bounded inbound JSON webhook events isolated per Application Environment."
                },
                "fr": {
                  "name": "Webhooks de l'application",
                  "summary": "Événements webhook JSON entrants, vérifiés et limités, isolés par environnement d’application."
                },
                "ru": {
                  "name": "Вебхуки приложения",
                  "summary": "Проверенные ограниченные входящие JSON-вебхуки, изолированные в среде приложения."
                }
              }
            },
            "sourcePath": "capabilities/APP_WEBHOOKS.md",
            "selectionMetadata": {
              "schemaVersion": "aqteron.builder.selection_metadata.v1",
              "summary": "Verified bounded inbound JSON webhook events isolated per Application Environment.",
              "userNeeds": [
                "receive signed events from an external provider",
                "consume bounded verified JSON callbacks",
                "avoid exposing webhook signing material to browser code"
              ],
              "selectionSignals": [
                "the provider can send HMAC-SHA256 signed JSON to a stable app webhook endpoint",
                "bounded retention and polling are sufficient"
              ],
              "exclusions": [
                "unsigned callbacks, arbitrary request bodies, raw credential transport, or custom webhook servers"
              ],
              "dependencies": [
                "app_secrets@1"
              ],
              "compatibility": {
                "contracts": [
                  "Aqteron PWA v1"
                ],
                "requires": [
                  "app_secrets@1"
                ],
                "conflicts": []
              },
              "runtime": {
                "adapterId": "app_webhooks@1"
              },
              "availability": {
                "instructionStatus": "draft",
                "registryStatus": "available",
                "runtimeStatus": "runtime_available",
                "builderSelectable": true,
                "instructionVisible": true,
                "entitlementAuthority": "aqteron_validator_runtime",
                "notSelectableReason": null
              }
            },
            "selfCheckMetadata": {
              "schemaVersion": "aqteron.builder.module_self_check.v1",
              "instructionModuleId": "aqteron.capability.app_webhooks@1",
              "moduleKind": "capability",
              "required": true,
              "appliesWhenSelected": true,
              "sourceHeading": "Module self-check",
              "checks": [
                {
                  "id": "declared_hook",
                  "text": "every webhook consumed by the app has a declared safe hook ID"
                },
                {
                  "id": "signing_ref_declared",
                  "text": "every hook signing reference exists in `app_secrets@1`"
                },
                {
                  "id": "bounded_inbound",
                  "text": "body size, retention, and event count are bounded"
                },
                {
                  "id": "verified_events_only",
                  "text": "browser code consumes only verified events through managed status/poll/ack helpers"
                },
                {
                  "id": "no_signing_secret_exposure",
                  "text": "signing secrets are never embedded or returned to browser code"
                },
                {
                  "id": "app_user_dependency",
                  "text": "`authMode: \"app_user\"` also declares enabled `app_users@1` when used"
                }
              ]
            }
          },
          "createdAt": "2026-09-21T10:50:00.000Z",
          "updatedAt": "2026-09-21T10:50:00.000Z"
        },
        {
          "capabilityKey": "external_api_proxy@1",
          "instructionModuleId": "aqteron.capability.external_api_proxy@1",
          "instructionModuleVersionId": "aqteron.capability.external_api_proxy@1@0.1.0",
          "registryStatus": "available",
          "displayName": "External API Proxy",
          "summary": "Allowlisted bounded HTTPS calls with server-held authentication and SSRF protection.",
          "metadata": {
            "runtimeStatus": "runtime_available",
            "builderSelectable": true,
            "instructionVisible": true,
            "entitlementAuthority": "aqteron_validator_runtime",
            "presentation": {
              "locales": {
                "en": {
                  "name": "External API Proxy",
                  "summary": "Allowlisted bounded HTTPS calls with server-held authentication and SSRF protection."
                },
                "fr": {
                  "name": "Proxy d'API externe",
                  "summary": "Appels HTTPS limités vers des domaines autorisés, avec authentification côté serveur et protection SSRF."
                },
                "ru": {
                  "name": "Прокси внешнего API",
                  "summary": "Ограниченные HTTPS-вызовы к разрешённым доменам с серверной аутентификацией и защитой от SSRF."
                }
              }
            },
            "sourcePath": "capabilities/EXTERNAL_API_PROXY.md",
            "selectionMetadata": {
              "schemaVersion": "aqteron.builder.selection_metadata.v1",
              "summary": "Allowlisted bounded HTTPS calls with server-held authentication and SSRF protection.",
              "userNeeds": [
                "call a specific approved external HTTPS API",
                "use server-held authentication for a third-party provider",
                "keep outbound network access bounded and auditable"
              ],
              "selectionSignals": [
                "the workflow explicitly depends on one or more known public API domains",
                "declared methods, body sizes, timeouts, and quotas are sufficient",
                "the provider can be called without arbitrary headers or redirects"
              ],
              "exclusions": [
                "arbitrary internet access, crawling, private/internal URLs, custom ports, raw sockets, or browser automation",
                "client-supplied Authorization/Cookie headers or absolute URLs"
              ],
              "dependencies": [
                "app_secrets@1"
              ],
              "compatibility": {
                "contracts": [
                  "Aqteron PWA v1"
                ],
                "requires": [
                  "app_secrets@1"
                ],
                "conflicts": []
              },
              "runtime": {
                "adapterId": "external_api_proxy@1"
              },
              "availability": {
                "instructionStatus": "draft",
                "registryStatus": "available",
                "runtimeStatus": "runtime_available",
                "builderSelectable": true,
                "instructionVisible": true,
                "entitlementAuthority": "aqteron_validator_runtime",
                "notSelectableReason": null
              }
            },
            "selfCheckMetadata": {
              "schemaVersion": "aqteron.builder.module_self_check.v1",
              "instructionModuleId": "aqteron.capability.external_api_proxy@1",
              "moduleKind": "capability",
              "required": true,
              "appliesWhenSelected": true,
              "sourceHeading": "Module self-check",
              "checks": [
                {
                  "id": "declared_domain_method",
                  "text": "every external API domain and HTTP method used by the app is explicitly declared"
                },
                {
                  "id": "server_held_auth",
                  "text": "authentication uses only declared `app_secrets@1` references"
                },
                {
                  "id": "relative_request_only",
                  "text": "generated code sends only domain, method, relative path, bounded query, and optional JSON body"
                },
                {
                  "id": "no_client_headers_or_url",
                  "text": "no absolute URL, arbitrary headers, Authorization/Cookie value, protocol, port, host override, or IP target is client supplied"
                },
                {
                  "id": "bounded_network_limits",
                  "text": "timeout, request bytes, response bytes, and requests-per-minute quota are declared and bounded"
                },
                {
                  "id": "app_user_dependency",
                  "text": "`authMode: \"app_user\"` also declares enabled `app_users@1`"
                },
                {
                  "id": "managed_helper_only",
                  "text": "generated code uses only the managed external API helper"
                }
              ]
            }
          },
          "createdAt": "2026-09-21T10:50:00.000Z",
          "updatedAt": "2026-09-21T10:50:00.000Z"
        },
        {
          "capabilityKey": "push_notifications@1",
          "instructionModuleId": "aqteron.capability.push_notifications@1",
          "instructionModuleVersionId": "aqteron.capability.push_notifications@1@0.1.5",
          "registryStatus": "available",
          "displayName": "Push Notifications",
          "summary": "Platform-managed push notification subscription and declared trigger support.",
          "metadata": {
            "runtimeStatus": "runtime_available",
            "builderSelectable": true,
            "instructionVisible": true,
            "entitlementAuthority": "aqteron_validator_runtime",
            "presentation": {
              "locales": {
                "en": {
                  "name": "Push Notifications",
                  "summary": "Platform-managed push notification subscription and declared trigger support."
                },
                "fr": {
                  "name": "Notifications push",
                  "summary": "Abonnements aux notifications push gérés par la plateforme et prise en charge des déclencheurs déclarés."
                },
                "ru": {
                  "name": "Push-уведомления",
                  "summary": "Управляемые платформой подписки на push-уведомления и поддержка объявленных триггеров."
                }
              }
            },
            "sourcePath": "capabilities/PUSH_NOTIFICATIONS.md",
            "selectionMetadata": {
              "schemaVersion": "aqteron.builder.selection_metadata.v1",
              "summary": "Platform-managed push notification subscription and declared trigger support.",
              "userNeeds": [
                "notify users while the installed or browser PWA is closed",
                "support declared message, reminder, or shared-data alerts",
                "let users subscribe, unsubscribe, and manage notification preferences"
              ],
              "selectionSignals": [
                "user explicitly needs push or closed-app alerts",
                "notification trigger fits the supported platform contract",
                "helper-only subscription controls are sufficient"
              ],
              "exclusions": [
                "custom service workers or direct push provider calls",
                "invented send endpoints or arbitrary server triggers",
                "storing browser subscription secrets in app state"
              ],
              "dependencies": [],
              "compatibility": {
                "contracts": [
                  "Aqteron PWA v1"
                ],
                "requires": [],
                "conflicts": []
              },
              "runtime": {
                "adapterId": null
              },
              "availability": {
                "instructionStatus": "draft",
                "registryStatus": "available",
                "runtimeStatus": "runtime_available",
                "builderSelectable": true,
                "instructionVisible": true,
                "entitlementAuthority": "aqteron_validator_runtime",
                "notSelectableReason": null
              }
            },
            "selfCheckMetadata": {
              "schemaVersion": "aqteron.builder.module_self_check.v1",
              "instructionModuleId": "aqteron.capability.push_notifications@1",
              "moduleKind": "capability",
              "required": true,
              "appliesWhenSelected": true,
              "sourceHeading": "Module self-check",
              "checks": [
                {
                  "id": "declared_when_helper_used",
                  "text": "`push_notifications@1` is declared when notifications helper is used"
                },
                {
                  "id": "supported_methods_only",
                  "text": "only supported helper methods are called and no `send()` exists"
                },
                {
                  "id": "no_app_service_worker_or_provider",
                  "text": "no application service worker or push-provider endpoint is included"
                },
                {
                  "id": "identity_mode_flow",
                  "text": "identity flow matches the app: with `app_users@1`, push uses the trusted app-user session and never calls `connectAccount()`; without it, legacy account linking and permission remain separate explicit user actions"
                },
                {
                  "id": "no_client_recipient_identity_authority",
                  "text": "no client-supplied user identity is treated as recipient ownership authority"
                },
                {
                  "id": "declared_database_trigger_fields",
                  "text": "triggers use declared `app_database.record.create` fields"
                },
                {
                  "id": "push_create_trigger_uses_create_path",
                  "text": "every `app_database.record.create` trigger record uses the `appDatabase.put` create path, including offline/deferred replay"
                },
                {
                  "id": "bounded_trigger_fields",
                  "text": "actor/target/click URL fields exist as bounded strings in the database schema"
                },
                {
                  "id": "same_app_click_url",
                  "text": "click URL is root-relative and same-app"
                },
                {
                  "id": "bounded_non_private_content",
                  "text": "notification title/body are bounded and do not expose private message contents"
                },
                {
                  "id": "opaque_recipient_ids",
                  "text": "opaque recipient IDs are not treated as secrets or modified"
                }
              ]
            }
          },
          "createdAt": "2026-09-16T05:00:00.000Z",
          "updatedAt": "2026-09-21T05:10:00.000Z"
        },
        {
          "capabilityKey": "realtime_events@1",
          "instructionModuleId": "aqteron.capability.realtime_events@1",
          "instructionModuleVersionId": "aqteron.capability.realtime_events@1@0.1.1",
          "registryStatus": "available",
          "displayName": "Realtime Events",
          "summary": "Bounded app/user-scoped live update signals with reconnect and replay.",
          "metadata": {
            "runtimeStatus": "runtime_available",
            "builderSelectable": true,
            "instructionVisible": true,
            "entitlementAuthority": "aqteron_validator_runtime",
            "presentation": {
              "locales": {
                "en": {
                  "name": "Realtime Events",
                  "summary": "Bounded app/user-scoped live update signals with reconnect and replay."
                },
                "fr": {
                  "name": "Événements temps réel",
                  "summary": "Signaux de mise à jour en temps réel limités, par application ou utilisateur, avec reconnexion et relecture."
                },
                "ru": {
                  "name": "События реального времени",
                  "summary": "Ограниченные realtime-события приложения или пользователя с переподключением и повторным чтением."
                }
              }
            },
            "sourcePath": "capabilities/REALTIME_EVENTS.md",
            "selectionMetadata": {
              "schemaVersion": "aqteron.builder.selection_metadata.v1",
              "summary": "Bounded app/user-scoped live update signals with reconnect and replay.",
              "userNeeds": [
                "update an already-open app quickly when durable shared state changes",
                "show message/status/read-state/presence changes without manual refresh",
                "replay a bounded window of missed live update signals after reconnect"
              ],
              "selectionSignals": [
                "the workflow has multi-tab, multi-device, or multi-user live updates",
                "durable records remain in app_database@1 while realtime only signals changes",
                "bounded long-poll transport with replay is sufficient"
              ],
              "exclusions": [
                "durable business-data history or unbounded event logs",
                "custom WebSocket/SSE servers or arbitrary backend realtime infrastructure",
                "large payloads, files, credentials, secrets, or raw session/user identity transport"
              ],
              "dependencies": [],
              "compatibility": {
                "contracts": [
                  "Aqteron PWA v1"
                ],
                "requires": [],
                "conflicts": []
              },
              "runtime": {
                "adapterId": "realtime_events@1"
              },
              "availability": {
                "instructionStatus": "draft",
                "registryStatus": "available",
                "runtimeStatus": "runtime_available",
                "builderSelectable": true,
                "instructionVisible": true,
                "entitlementAuthority": "aqteron_validator_runtime",
                "notSelectableReason": null
              }
            },
            "selfCheckMetadata": {
              "schemaVersion": "aqteron.builder.module_self_check.v1",
              "instructionModuleId": "aqteron.capability.realtime_events@1",
              "moduleKind": "capability",
              "required": true,
              "appliesWhenSelected": true,
              "sourceHeading": "Module self-check",
              "checks": [
                {
                  "id": "declared_when_helper_used",
                  "text": "`realtime_events@1` is declared whenever `realtimeEvents` is used"
                },
                {
                  "id": "supported_methods_only",
                  "text": "only the exact managed `status`, `publish`, `poll`, and `subscribe` helper methods are used"
                },
                {
                  "id": "channels_types_declared",
                  "text": "every used channel and event type is declared"
                },
                {
                  "id": "bounded_limits",
                  "text": "each channel has bounded retention, event count, and payload size within the exact platform limits"
                },
                {
                  "id": "app_user_dependency",
                  "text": "`app_user` channels also declare enabled `app_users@1`"
                },
                {
                  "id": "no_client_authority",
                  "text": "no client-supplied app/user/subject/session/storage identifier is used as authorization authority"
                },
                {
                  "id": "durable_data_separate",
                  "text": "durable business records remain in `app_database@1` or another appropriate durable capability"
                },
                {
                  "id": "cursor_reset_refreshes",
                  "text": "cursor reset causes an authoritative state refresh instead of guessing missing events"
                },
                {
                  "id": "bounded_subscribe_retry",
                  "text": "subscribe retry uses a bounded exponential backoff with a single in-flight poll"
                },
                {
                  "id": "no_reconnect_amplification",
                  "text": "reconnect preserves the cursor and does not republish replay/presence events automatically"
                },
                {
                  "id": "presence_ephemeral",
                  "text": "presence is treated only as an ephemeral hint"
                },
                {
                  "id": "no_sensitive_payloads",
                  "text": "realtime payloads contain no secrets, credentials, raw session tokens, files, or large/private record bodies"
                }
              ]
            }
          },
          "createdAt": "2026-09-21T05:40:00.000Z",
          "updatedAt": "2026-09-22T04:20:00.000Z"
        },
        {
          "capabilityKey": "web_parser@1",
          "instructionModuleId": "aqteron.capability.web_parser@1",
          "instructionModuleVersionId": "aqteron.capability.web_parser@1@0.1.4",
          "registryStatus": "available",
          "displayName": "Web Parser",
          "summary": "Bounded readable-text parsing for explicitly approved public domains.",
          "metadata": {
            "runtimeStatus": "runtime_available",
            "builderSelectable": true,
            "instructionVisible": true,
            "entitlementAuthority": "aqteron_validator_runtime",
            "presentation": {
              "locales": {
                "en": {
                  "name": "Web Parser",
                  "summary": "Bounded readable-text parsing for explicitly approved public domains."
                },
                "fr": {
                  "name": "Analyseur web",
                  "summary": "Extraction limitée de texte lisible depuis des domaines publics explicitement approuvés."
                },
                "ru": {
                  "name": "Веб-парсер",
                  "summary": "Ограниченное извлечение читаемого текста с явно разрешённых публичных доменов."
                }
              }
            },
            "sourcePath": "capabilities/WEB_PARSER.md",
            "selectionMetadata": {
              "schemaVersion": "aqteron.builder.selection_metadata.v1",
              "summary": "Bounded readable-text parsing for explicitly approved public domains.",
              "userNeeds": [
                "read sanitized text from approved public HTTP(S) pages",
                "extract readable text from a specific public URL",
                "use public web text inside an Aqteron workflow"
              ],
              "selectionSignals": [
                "live generation context marks this module usable for the account",
                "source pages are public, readable, and approved",
                "readable_text output is sufficient"
              ],
              "exclusions": [
                "login-only, private, internal, localhost, or metadata URLs",
                "broad crawling, screenshots, binary downloads, raw HTML execution, or browser automation"
              ],
              "dependencies": [],
              "compatibility": {
                "contracts": [
                  "Aqteron PWA v1"
                ],
                "requires": [],
                "conflicts": []
              },
              "runtime": {
                "adapterId": "web_parser@1"
              },
              "availability": {
                "instructionStatus": "draft",
                "registryStatus": "available",
                "runtimeStatus": "runtime_available",
                "builderSelectable": true,
                "instructionVisible": true,
                "entitlementAuthority": "aqteron_validator_runtime",
                "notSelectableReason": null
              }
            },
            "selfCheckMetadata": {
              "schemaVersion": "aqteron.builder.module_self_check.v1",
              "instructionModuleId": "aqteron.capability.web_parser@1",
              "moduleKind": "capability",
              "required": true,
              "appliesWhenSelected": true,
              "sourceHeading": "Module self-check",
              "checks": [
                {
                  "id": "workflow_needs_public_text",
                  "text": "the user workflow genuinely needs public readable text"
                },
                {
                  "id": "requested_domains_declared",
                  "text": "every requested domain is explicitly declared"
                },
                {
                  "id": "readable_text_only",
                  "text": "only `readable_text` is requested"
                },
                {
                  "id": "no_login_or_auth_forwarding",
                  "text": "no login/session/cookie/Auth forwarding is attempted"
                },
                {
                  "id": "no_private_targets",
                  "text": "no private/internal/localhost/IP target is accepted"
                },
                {
                  "id": "no_direct_scraping",
                  "text": "no direct cross-origin scraping/headless crawling is implemented"
                },
                {
                  "id": "declaration_request_agree",
                  "text": "capability declaration and request URL agree"
                },
                {
                  "id": "platform_errors_user_facing",
                  "text": "platform errors are shown in user-facing form"
                }
              ]
            }
          },
          "createdAt": "2026-09-16T05:00:00.000Z",
          "updatedAt": "2026-09-16T05:00:00.000Z"
        },
        {
          "capabilityKey": "webrtc_signaling@1",
          "instructionModuleId": "aqteron.capability.webrtc_signaling@1",
          "instructionModuleVersionId": "aqteron.capability.webrtc_signaling@1@0.1.6",
          "registryStatus": "available",
          "displayName": "WebRTC Signaling",
          "summary": "Short-lived app-scoped signaling for browser peer-to-peer WebRTC setup.",
          "metadata": {
            "runtimeStatus": "runtime_available",
            "builderSelectable": true,
            "instructionVisible": true,
            "entitlementAuthority": "aqteron_validator_runtime",
            "presentation": {
              "locales": {
                "en": {
                  "name": "WebRTC Signaling",
                  "summary": "Short-lived app-scoped signaling for browser peer-to-peer WebRTC setup."
                },
                "fr": {
                  "name": "Signalisation WebRTC",
                  "summary": "Signalisation temporaire propre à l'application pour établir des connexions WebRTC pair à pair."
                },
                "ru": {
                  "name": "Сигналинг WebRTC",
                  "summary": "Краткоживущий сигналинг приложения для установки браузерных WebRTC-соединений peer-to-peer."
                }
              }
            },
            "sourcePath": "capabilities/WEBRTC_SIGNALING.md",
            "selectionMetadata": {
              "schemaVersion": "aqteron.builder.selection_metadata.v1",
              "summary": "Short-lived app-scoped signaling for browser peer-to-peer WebRTC setup.",
              "userNeeds": [
                "coordinate browser peer-to-peer audio, video, or data channel setup",
                "exchange short-lived WebRTC signaling messages",
                "support real-time peer connection workflows"
              ],
              "selectionSignals": [
                "live generation context marks this module usable for the account",
                "application needs WebRTC signaling with platform-managed relay fallback when direct connectivity fails",
                "short-lived helper-mediated signaling and managed ICE credentials are sufficient"
              ],
              "exclusions": [
                "media recording, SFU/media processing, custom TURN/STUN credential management, or persistent chat storage",
                "storing SDP or ICE payloads in app_database@1"
              ],
              "dependencies": [],
              "compatibility": {
                "contracts": [
                  "Aqteron PWA v1"
                ],
                "requires": [],
                "conflicts": []
              },
              "runtime": {
                "adapterId": "webrtc_signaling@1"
              },
              "availability": {
                "instructionStatus": "draft",
                "registryStatus": "available",
                "runtimeStatus": "runtime_available",
                "builderSelectable": true,
                "instructionVisible": true,
                "entitlementAuthority": "aqteron_validator_runtime",
                "notSelectableReason": null
              }
            },
            "selfCheckMetadata": {
              "schemaVersion": "aqteron.builder.module_self_check.v1",
              "instructionModuleId": "aqteron.capability.webrtc_signaling@1",
              "moduleKind": "capability",
              "required": true,
              "appliesWhenSelected": true,
              "sourceHeading": "Module self-check",
              "checks": [
                {
                  "id": "declared_when_helper_used",
                  "text": "the capability is declared if signaling helper is used"
                },
                {
                  "id": "signaling_not_database_persisted",
                  "text": "signaling data is not persisted in `app_database@1`"
                },
                {
                  "id": "no_custom_signaling_route",
                  "text": "no private/custom signaling server route is invented"
                },
                {
                  "id": "bounded_payload_and_ttl",
                  "text": "payload size and TTL are bounded"
                },
                {
                  "id": "managed_turn_media_boundary",
                  "text": "media remains browser WebRTC traffic; managed TURN is only an encrypted-packet relay and is not recording or media processing"
                },
                {
                  "id": "managed_turn_helper_only",
                  "text": "ICE configuration comes only from the platform helper; no hardcoded relay credentials or routes are embedded"
                },
                {
                  "id": "managed_turn_ephemeral",
                  "text": "short-lived managed TURN credentials are never persisted and are refreshed for new/recovered calls"
                },
                {
                  "id": "participant_resume_bounded",
                  "text": "participant recovery uses only the server-issued volatile `resumeToken` and bounded `participant.resume` retries"
                },
                {
                  "id": "app_user_resume_continuity",
                  "text": "app-user-bound participants cannot resume as a different trusted app user"
                },
                {
                  "id": "no_blind_signal_retry",
                  "text": "non-idempotent signaling sends are not blindly retried"
                },
                {
                  "id": "recovery_cursor_continuity",
                  "text": "recovery continues from the last signaling sequence rather than replaying from zero"
                },
                {
                  "id": "visible_failure_states",
                  "text": "call failure and unsupported-environment states are shown to the user"
                }
              ]
            }
          },
          "createdAt": "2026-09-16T05:00:00.000Z",
          "updatedAt": "2026-09-22T04:20:00.000Z"
        }
      ]
    },
    "createdAt": "2026-09-22T04:20:00.000Z",
    "createdBy": "block14-reliability-production"
  },
  "modulePins": [
    {
      "instructionModuleId": "aqteron.builder.core",
      "instructionModuleVersionId": "aqteron.builder.core@0.2.6",
      "moduleKey": "aqteron.builder.core",
      "moduleKind": "core",
      "displayName": "Aqteron Builder Core",
      "description": "",
      "sourcePath": "BUILDER_CORE.md",
      "versionLabel": "0.2.6",
      "contentSha256": "c15131e44427fb0f47a422e4fa46e7c1da75ddec0848b8a5d7a8c1eb0d62f8aa",
      "moduleMetadata": {
        "sourcePath": "BUILDER_CORE.md",
        "instructionId": "aqteron.builder.core"
      },
      "versionMetadata": {
        "status": "draft",
        "contract": "Aqteron PWA v1",
        "sourcePath": "BUILDER_CORE.md",
        "instructionSet": {
          "id": "aqteron.app-generation",
          "version": "0.2.11"
        },
        "dependencies": []
      },
      "pinnedAt": "2026-09-22T04:20:00.000Z",
      "pinnedBy": "block14-reliability-production"
    },
    {
      "instructionModuleId": "aqteron.capability.app_database@1",
      "instructionModuleVersionId": "aqteron.capability.app_database@1@0.1.5",
      "moduleKey": "aqteron.capability.app_database@1",
      "moduleKind": "capability",
      "displayName": "Aqteron Capability: app_database@1",
      "description": "",
      "sourcePath": "capabilities/APP_DATABASE.md",
      "versionLabel": "0.1.5",
      "contentSha256": "52e1ab38d67951ff4c4840fd0212ac1bf86a4f883d218d20d3589564c6caa2f6",
      "moduleMetadata": {
        "sourcePath": "capabilities/APP_DATABASE.md",
        "instructionId": "aqteron.capability.app_database@1"
      },
      "versionMetadata": {
        "status": "draft",
        "contract": "Aqteron PWA v1",
        "sourcePath": "capabilities/APP_DATABASE.md",
        "instructionSet": {
          "id": "aqteron.app-generation",
          "version": "0.2.16"
        },
        "dependencies": [],
        "capabilityAvailability": {
          "capabilityKey": "app_database@1",
          "registryStatus": "available",
          "runtimeStatus": "runtime_available",
          "builderSelectable": true,
          "instructionVisible": true,
          "entitlementAuthority": "aqteron_validator_runtime"
        },
        "selectionMetadata": {
          "schemaVersion": "aqteron.builder.selection_metadata.v1",
          "summary": "App-scoped JSON record storage for shared or cross-device persistence.",
          "userNeeds": [
            "persist structured records beyond one browser or install",
            "share app-scoped records across linked users or devices",
            "store bounded server-side JSON records"
          ],
          "selectionSignals": [
            "localStorage or IndexedDB is insufficient",
            "records must survive reinstall or device changes",
            "multiple users or devices need the same app data"
          ],
          "exclusions": [
            "file, image, document, or attachment storage",
            "raw SQL or arbitrary backend database access",
            "secrets, credentials, passwords, tokens, or private keys"
          ],
          "dependencies": [],
          "compatibility": {
            "contracts": [
              "Aqteron PWA v1"
            ],
            "requires": [],
            "conflicts": []
          },
          "runtime": {
            "adapterId": "app_database@1"
          },
          "availability": {
            "instructionStatus": "draft",
            "registryStatus": "available",
            "runtimeStatus": "runtime_available",
            "builderSelectable": true,
            "instructionVisible": true,
            "entitlementAuthority": "aqteron_validator_runtime",
            "notSelectableReason": null
          }
        },
        "selfCheckMetadata": {
          "schemaVersion": "aqteron.builder.module_self_check.v1",
          "instructionModuleId": "aqteron.capability.app_database@1",
          "moduleKind": "capability",
          "required": true,
          "appliesWhenSelected": true,
          "sourceHeading": "Module self-check",
          "checks": [
            {
              "id": "declared_when_helper_used",
              "text": "capability is declared when JavaScript uses `appDatabase`"
            },
            {
              "id": "used_collections_declared",
              "text": "every used collection is declared"
            },
            {
              "id": "schema_keys_match",
              "text": "schema and JS keys are identical lower_snake_case ASCII"
            },
            {
              "id": "no_undeclared_fields",
              "text": "no undeclared extra fields are written"
            },
            {
              "id": "new_record_uses_put",
              "text": "every new logical record uses `put` with declared `record.create`"
            },
            {
              "id": "existing_record_uses_set",
              "text": "every existing logical record update uses `set` with declared `record.update`"
            },
            {
              "id": "offline_replay_preserves_intent",
              "text": "offline/deferred replay preserves `put` versus `set` operation intent"
            },
            {
              "id": "bounded_list_limit",
              "text": "every `list` call has an explicit numeric limit from 1 to 100"
            },
            {
              "id": "db_list_limit_not_record_quota",
              "text": "a `list` retrieval limit is not treated as the collection `maxRecords` quota"
            },
            {
              "id": "no_raw_secrets",
              "text": "no raw secrets are persisted"
            },
            {
              "id": "no_private_database_routes",
              "text": "no direct/private database routes or raw SQL are used"
            },
            {
              "id": "app_user_server_authority",
              "text": "when `authMode: \"app_user\"` is selected, `app_users@1` is enabled and authorization comes only from the trusted server-resolved app-user session"
            },
            {
              "id": "no_client_identity_or_row_privacy_claim",
              "text": "no client-supplied user identity is treated as authority and no row-level privacy is claimed from `authMode` alone"
            },
            {
              "id": "user_readable_errors",
              "text": "capability failures produce user-readable UI errors"
            }
          ]
        }
      },
      "pinnedAt": "2026-09-22T04:20:00.000Z",
      "pinnedBy": "block14-reliability-production"
    },
    {
      "instructionModuleId": "aqteron.capability.app_files@1",
      "instructionModuleVersionId": "aqteron.capability.app_files@1@0.3.1",
      "moduleKey": "aqteron.capability.app_files@1",
      "moduleKind": "capability",
      "displayName": "Aqteron Capability: app_files@1",
      "description": "",
      "sourcePath": "capabilities/APP_FILES.md",
      "versionLabel": "0.3.1",
      "contentSha256": "3c184d3714879bedcbdb009e553667034902170d6677589b2b5d05f4bfb14541",
      "moduleMetadata": {
        "sourcePath": "capabilities/APP_FILES.md",
        "instructionId": "aqteron.capability.app_files@1"
      },
      "versionMetadata": {
        "status": "activation_candidate",
        "contract": "Aqteron PWA v1",
        "sourcePath": "capabilities/APP_FILES.md",
        "instructionSet": {
          "id": "aqteron.app-generation",
          "version": "0.2.16"
        },
        "dependencies": [],
        "capabilityAvailability": {
          "capabilityKey": "app_files@1",
          "registryStatus": "available",
          "runtimeStatus": "runtime_available",
          "builderSelectable": true,
          "instructionVisible": true,
          "entitlementAuthority": "aqteron_validator_runtime"
        },
        "selectionMetadata": {
          "schemaVersion": "aqteron.builder.selection_metadata.v1",
          "summary": "Guarded private file storage for entitled applications when canonical readiness controls pass.",
          "userNeeds": [
            "store user files, attachments, images, documents, imports, or exports",
            "keep private application-scoped files in managed storage",
            "associate files with app workflows"
          ],
          "selectionSignals": [
            "managed private files are required and server-side entitlement is available",
            "files must persist outside local browser storage",
            "workflow references uploaded or generated files"
          ],
          "exclusions": [
            "workflows that can remain entirely in local browser storage",
            "public hosting or public URL generation",
            "shared-drive behavior across unrelated apps or users",
            "structured JSON record storage without files"
          ],
          "dependencies": [],
          "compatibility": {
            "contracts": [
              "Aqteron PWA v1"
            ],
            "requires": [],
            "conflicts": []
          },
          "runtime": {
            "adapterId": "app_files@1"
          },
          "availability": {
            "instructionStatus": "activation_candidate",
            "registryStatus": "available",
            "runtimeStatus": "runtime_available",
            "builderSelectable": true,
            "instructionVisible": true,
            "entitlementAuthority": "aqteron_validator_runtime",
            "notSelectableReason": null
          }
        },
        "selfCheckMetadata": {
          "schemaVersion": "aqteron.builder.module_self_check.v1",
          "instructionModuleId": "aqteron.capability.app_files@1",
          "moduleKind": "capability",
          "required": true,
          "appliesWhenSelected": true,
          "sourceHeading": "Module self-check",
          "checks": [
            {
              "id": "declared_when_helper_used",
              "text": "capability is declared if `appFiles` is used"
            },
            {
              "id": "only_prompt2app_helper",
              "text": "only the exact `window.Prompt2App.appFiles` methods above are used"
            },
            {
              "id": "subject_mode_identity_matches",
              "text": "identity handling matches the declared subject mode: `app_user` requires trusted app-local sign-in, `app` does not account-link, and only legacy no-`subjectMode` declarations may call `connectAccount()`"
            },
            {
              "id": "no_client_file_identity_authority",
              "text": "no client-provided user/subject identifier is used as file authorization authority"
            },
            {
              "id": "used_buckets_declared_private",
              "text": "every used bucket is declared and private"
            },
            {
              "id": "file_quota_dimensions_coherent",
              "text": "MIME types are bounded and `maxFileSizeBytes`, `maxTotalBytes`, and `maxFiles` are validated as separate dimensions within their exact ceilings"
            },
            {
              "id": "mixed_db_files_fixture_coherent",
              "text": "mixed database/file workflows keep database `list` limits, database `maxRecords`, and file `maxFiles` distinct and dimensionally coherent"
            },
            {
              "id": "exact_file_transport",
              "text": "file inputs are browser `File` values and downloads use `contentBase64`"
            },
            {
              "id": "no_invented_storage_authority",
              "text": "no public/presigned/storage URLs, filesystem paths, internal metadata, or unsupported sharing are invented"
            },
            {
              "id": "server_entitlement_authority",
              "text": "server entitlement is never inferred from the package"
            },
            {
              "id": "visible_errors",
              "text": "errors are visible and do not falsely report successful storage"
            }
          ]
        }
      },
      "pinnedAt": "2026-09-22T04:20:00.000Z",
      "pinnedBy": "block14-reliability-production"
    },
    {
      "instructionModuleId": "aqteron.capability.app_jobs@1",
      "instructionModuleVersionId": "aqteron.capability.app_jobs@1@0.1.0",
      "moduleKey": "aqteron.capability.app_jobs@1",
      "moduleKind": "capability",
      "displayName": "App Jobs",
      "description": "Bounded delayed and retryable external API actions executed by a managed worker.",
      "sourcePath": "capabilities/APP_JOBS.md",
      "versionLabel": "0.1.0",
      "contentSha256": "bbecf7d4dbb15939472be98dc253825c383cce1a7030ca62cd68c283903c84d6",
      "moduleMetadata": {
        "sourcePath": "capabilities/APP_JOBS.md",
        "instructionId": "aqteron.capability.app_jobs@1"
      },
      "versionMetadata": {
        "status": "draft",
        "contract": "Aqteron PWA v1",
        "sourcePath": "capabilities/APP_JOBS.md",
        "instructionSet": {
          "id": "aqteron.app-generation",
          "version": "0.2.18"
        },
        "dependencies": [
          {
            "instructionModuleId": "aqteron.capability.app_secrets@1",
            "instructionModuleVersionId": "aqteron.capability.app_secrets@1@0.1.0"
          },
          {
            "instructionModuleId": "aqteron.capability.external_api_proxy@1",
            "instructionModuleVersionId": "aqteron.capability.external_api_proxy@1@0.1.0"
          }
        ],
        "capabilityAvailability": {
          "capabilityKey": "app_jobs@1",
          "registryStatus": "available",
          "runtimeStatus": "runtime_available",
          "builderSelectable": true,
          "instructionVisible": true,
          "entitlementAuthority": "aqteron_validator_runtime"
        },
        "selectionMetadata": {
          "schemaVersion": "aqteron.builder.selection_metadata.v1",
          "summary": "Bounded delayed and retryable external API actions executed by a managed worker.",
          "userNeeds": [
            "run an approved external API action later",
            "retry transient external API failures with bounded backoff",
            "inspect and cancel pending managed jobs"
          ],
          "selectionSignals": [
            "the scheduled work is representable as an external_api_proxy request descriptor",
            "one-time delayed execution and bounded retries are sufficient"
          ],
          "exclusions": [
            "arbitrary code execution, cron scripts, unbounded recurring tasks, raw secrets in payloads, or custom background servers"
          ],
          "dependencies": [
            "external_api_proxy@1",
            "app_secrets@1"
          ],
          "compatibility": {
            "contracts": [
              "Aqteron PWA v1"
            ],
            "requires": [
              "external_api_proxy@1",
              "app_secrets@1"
            ],
            "conflicts": []
          },
          "runtime": {
            "adapterId": "app_jobs@1"
          },
          "availability": {
            "instructionStatus": "draft",
            "registryStatus": "available",
            "runtimeStatus": "runtime_available",
            "builderSelectable": true,
            "instructionVisible": true,
            "entitlementAuthority": "aqteron_validator_runtime",
            "notSelectableReason": null
          }
        },
        "selfCheckMetadata": {
          "schemaVersion": "aqteron.builder.module_self_check.v1",
          "instructionModuleId": "aqteron.capability.app_jobs@1",
          "moduleKind": "capability",
          "required": true,
          "appliesWhenSelected": true,
          "sourceHeading": "Module self-check",
          "checks": [
            {
              "id": "dependencies_declared",
              "text": "`external_api_proxy@1` and required `app_secrets@1` references are declared"
            },
            {
              "id": "request_allowlisted",
              "text": "every scheduled request satisfies the declared external API domain and method allowlist"
            },
            {
              "id": "bounded_schedule",
              "text": "run time, queue size, retry count, and retry delay stay inside declared bounds"
            },
            {
              "id": "idempotency_key",
              "text": "each logical scheduled action uses a stable non-secret idempotency key"
            },
            {
              "id": "no_raw_credentials",
              "text": "scheduled job payloads contain no raw credentials or arbitrary backend code"
            },
            {
              "id": "app_user_dependency",
              "text": "`authMode: \"app_user\"` also declares enabled `app_users@1`"
            },
            {
              "id": "managed_helper_only",
              "text": "generated code uses only the managed job status/schedule/list/get/cancel helpers"
            }
          ]
        }
      },
      "pinnedAt": "2026-09-22T04:20:00.000Z",
      "pinnedBy": "block14-reliability-production"
    },
    {
      "instructionModuleId": "aqteron.capability.app_secrets@1",
      "instructionModuleVersionId": "aqteron.capability.app_secrets@1@0.1.0",
      "moduleKey": "aqteron.capability.app_secrets@1",
      "moduleKind": "capability",
      "displayName": "App Secrets",
      "description": "Server-held encrypted credential references that are never exposed to generated app JavaScript.",
      "sourcePath": "capabilities/APP_SECRETS.md",
      "versionLabel": "0.1.0",
      "contentSha256": "f1b161d9d941227f90feeebc9634838384b36de590e756fa813c5e44b1509fd6",
      "moduleMetadata": {
        "sourcePath": "capabilities/APP_SECRETS.md",
        "instructionId": "aqteron.capability.app_secrets@1"
      },
      "versionMetadata": {
        "status": "draft",
        "contract": "Aqteron PWA v1",
        "sourcePath": "capabilities/APP_SECRETS.md",
        "instructionSet": {
          "id": "aqteron.app-generation",
          "version": "0.2.18"
        },
        "dependencies": [],
        "capabilityAvailability": {
          "capabilityKey": "app_secrets@1",
          "registryStatus": "available",
          "runtimeStatus": "runtime_available",
          "builderSelectable": true,
          "instructionVisible": true,
          "entitlementAuthority": "aqteron_validator_runtime"
        },
        "selectionMetadata": {
          "schemaVersion": "aqteron.builder.selection_metadata.v1",
          "summary": "Server-held encrypted credential references that are never exposed to generated app JavaScript.",
          "userNeeds": [
            "store third-party API credentials without exposing them to browser code",
            "let the app owner configure named server-held credential references",
            "rotate or revoke integration credentials without rebuilding the application"
          ],
          "selectionSignals": [
            "an external integration needs an API key, token, or signing secret",
            "the credential must remain server-side",
            "the user can configure the credential after publication"
          ],
          "exclusions": [
            "embedding raw credentials in ZIP files, metadata, JavaScript, browser storage, logs, or job payloads",
            "using app_secrets as general user data storage"
          ],
          "dependencies": [],
          "compatibility": {
            "contracts": [
              "Aqteron PWA v1"
            ],
            "requires": [],
            "conflicts": []
          },
          "runtime": {
            "adapterId": "app_secrets@1"
          },
          "availability": {
            "instructionStatus": "draft",
            "registryStatus": "available",
            "runtimeStatus": "runtime_available",
            "builderSelectable": true,
            "instructionVisible": true,
            "entitlementAuthority": "aqteron_validator_runtime",
            "notSelectableReason": null
          }
        },
        "selfCheckMetadata": {
          "schemaVersion": "aqteron.builder.module_self_check.v1",
          "instructionModuleId": "aqteron.capability.app_secrets@1",
          "moduleKind": "capability",
          "required": true,
          "appliesWhenSelected": true,
          "sourceHeading": "Module self-check",
          "checks": [
            {
              "id": "declared_when_needed",
              "text": "`app_secrets@1` is declared whenever server-held integration credentials are required"
            },
            {
              "id": "refs_declared",
              "text": "every credential reference used by another capability is declared in `config.refs`"
            },
            {
              "id": "no_raw_secret_in_package",
              "text": "no raw secret value appears in ZIP files, metadata, JavaScript, browser storage, logs, webhook payloads, or job payloads"
            },
            {
              "id": "status_only_browser",
              "text": "generated app code uses only status visibility and never expects a raw secret value"
            },
            {
              "id": "owner_configuration",
              "text": "the user-facing flow explains that the application owner configures the credential in Aqteron"
            },
            {
              "id": "rotation_safe",
              "text": "rotation or revocation does not require rebuilding the generated application"
            }
          ]
        }
      },
      "pinnedAt": "2026-09-22T04:20:00.000Z",
      "pinnedBy": "block14-reliability-production"
    },
    {
      "instructionModuleId": "aqteron.capability.app_users@1",
      "instructionModuleVersionId": "aqteron.capability.app_users@1@0.1.1",
      "moduleKey": "aqteron.capability.app_users@1",
      "moduleKind": "capability",
      "displayName": "App Users",
      "description": "",
      "sourcePath": "capabilities/APP_USERS.md",
      "versionLabel": "0.1.1",
      "contentSha256": "39de99146570c81ada8d019b085101d83f86d6ec03dccb3cace5a3a363c96dab",
      "moduleMetadata": {
        "sourcePath": "capabilities/APP_USERS.md",
        "instructionId": "aqteron.capability.app_users@1"
      },
      "versionMetadata": {
        "status": "draft",
        "contract": "Aqteron PWA v1",
        "sourcePath": "capabilities/APP_USERS.md",
        "instructionSet": {
          "id": "aqteron.app-generation",
          "version": "0.2.16"
        },
        "dependencies": [],
        "capabilityAvailability": {
          "capabilityKey": "app_users@1",
          "registryStatus": "available",
          "runtimeStatus": "runtime_available",
          "builderSelectable": true,
          "instructionVisible": true,
          "entitlementAuthority": "aqteron_validator_runtime"
        },
        "selectionMetadata": {
          "schemaVersion": "aqteron.builder.selection_metadata.v1",
          "summary": "Isolated application-local user accounts, sessions, roles, permissions, and credential recovery.",
          "userNeeds": [
            "let visitors create or use accounts that belong only to the application",
            "maintain application-local sign-in sessions across visits",
            "check application-local roles or permissions"
          ],
          "selectionSignals": [
            "the requested workflow needs sign-in that must not depend on Aqteron platform accounts",
            "multiple end users need distinct identities inside one published application",
            "managed credential hashing, lockout, recovery, or session revocation is required"
          ],
          "exclusions": [
            "Aqteron platform account authentication or account linking",
            "custom authentication servers or direct credential storage",
            "workflows that need no user identity"
          ],
          "dependencies": [],
          "compatibility": {
            "contracts": [
              "Aqteron PWA v1"
            ],
            "requires": [],
            "conflicts": []
          },
          "runtime": {
            "adapterId": "app_users@1"
          },
          "availability": {
            "instructionStatus": "draft",
            "registryStatus": "available",
            "runtimeStatus": "runtime_available",
            "builderSelectable": true,
            "instructionVisible": true,
            "entitlementAuthority": "aqteron_validator_runtime",
            "notSelectableReason": null
          }
        },
        "selfCheckMetadata": {
          "schemaVersion": "aqteron.builder.module_self_check.v1",
          "instructionModuleId": "aqteron.capability.app_users@1",
          "moduleKind": "capability",
          "required": true,
          "appliesWhenSelected": true,
          "sourceHeading": "Module self-check",
          "checks": [
            {
              "id": "declared_when_helper_used",
              "text": "`app_users@1` is declared whenever `appUsers` is used"
            },
            {
              "id": "supported_methods_only",
              "text": "only the exact `window.Prompt2App.appUsers` public methods above are used"
            },
            {
              "id": "platform_identity_separate",
              "text": "app users are never treated as Aqteron platform accounts"
            },
            {
              "id": "no_custom_auth_backend",
              "text": "no custom authentication backend or private app-user route is invented"
            },
            {
              "id": "no_raw_auth_secrets",
              "text": "raw passwords, PINs, recovery codes, session tokens, and cookies are never persisted by generated code"
            },
            {
              "id": "registration_mode_matches",
              "text": "registration UI matches the declared `registrationMode`"
            },
            {
              "id": "bounded_security_policy",
              "text": "credential types and session/lockout bounds match the declaration contract"
            },
            {
              "id": "permission_boundary",
              "text": "permission checks do not rely on hiding UI as server authorization"
            },
            {
              "id": "admin_ops_not_public",
              "text": "role assignment and recovery-code issuance are not exposed as public browser operations"
            },
            {
              "id": "trusted_cross_capability_authority",
              "text": "capability combinations that require app-user authority derive it only from the trusted server session and never from client-selected user IDs"
            },
            {
              "id": "current_binding_modes",
              "text": "per-user files use `subjectMode: \"app_user\"`, database sign-in gates use `authMode: \"app_user\"`, and push does not account-link when `app_users@1` is enabled"
            },
            {
              "id": "visible_auth_states",
              "text": "authentication, lockout, recovery, and unavailable states are shown clearly to the user"
            }
          ]
        }
      },
      "pinnedAt": "2026-09-22T04:20:00.000Z",
      "pinnedBy": "block14-reliability-production"
    },
    {
      "instructionModuleId": "aqteron.capability.app_webhooks@1",
      "instructionModuleVersionId": "aqteron.capability.app_webhooks@1@0.1.0",
      "moduleKey": "aqteron.capability.app_webhooks@1",
      "moduleKind": "capability",
      "displayName": "App Webhooks",
      "description": "Verified bounded inbound JSON webhook events isolated per Application Environment.",
      "sourcePath": "capabilities/APP_WEBHOOKS.md",
      "versionLabel": "0.1.0",
      "contentSha256": "ce9424ebce6996b5f6e3ef31ea7eb644e83644f2c46bcc22c01acede164749f1",
      "moduleMetadata": {
        "sourcePath": "capabilities/APP_WEBHOOKS.md",
        "instructionId": "aqteron.capability.app_webhooks@1"
      },
      "versionMetadata": {
        "status": "draft",
        "contract": "Aqteron PWA v1",
        "sourcePath": "capabilities/APP_WEBHOOKS.md",
        "instructionSet": {
          "id": "aqteron.app-generation",
          "version": "0.2.18"
        },
        "dependencies": [
          {
            "instructionModuleId": "aqteron.capability.app_secrets@1",
            "instructionModuleVersionId": "aqteron.capability.app_secrets@1@0.1.0"
          }
        ],
        "capabilityAvailability": {
          "capabilityKey": "app_webhooks@1",
          "registryStatus": "available",
          "runtimeStatus": "runtime_available",
          "builderSelectable": true,
          "instructionVisible": true,
          "entitlementAuthority": "aqteron_validator_runtime"
        },
        "selectionMetadata": {
          "schemaVersion": "aqteron.builder.selection_metadata.v1",
          "summary": "Verified bounded inbound JSON webhook events isolated per Application Environment.",
          "userNeeds": [
            "receive signed events from an external provider",
            "consume bounded verified JSON callbacks",
            "avoid exposing webhook signing material to browser code"
          ],
          "selectionSignals": [
            "the provider can send HMAC-SHA256 signed JSON to a stable app webhook endpoint",
            "bounded retention and polling are sufficient"
          ],
          "exclusions": [
            "unsigned callbacks, arbitrary request bodies, raw credential transport, or custom webhook servers"
          ],
          "dependencies": [
            "app_secrets@1"
          ],
          "compatibility": {
            "contracts": [
              "Aqteron PWA v1"
            ],
            "requires": [
              "app_secrets@1"
            ],
            "conflicts": []
          },
          "runtime": {
            "adapterId": "app_webhooks@1"
          },
          "availability": {
            "instructionStatus": "draft",
            "registryStatus": "available",
            "runtimeStatus": "runtime_available",
            "builderSelectable": true,
            "instructionVisible": true,
            "entitlementAuthority": "aqteron_validator_runtime",
            "notSelectableReason": null
          }
        },
        "selfCheckMetadata": {
          "schemaVersion": "aqteron.builder.module_self_check.v1",
          "instructionModuleId": "aqteron.capability.app_webhooks@1",
          "moduleKind": "capability",
          "required": true,
          "appliesWhenSelected": true,
          "sourceHeading": "Module self-check",
          "checks": [
            {
              "id": "declared_hook",
              "text": "every webhook consumed by the app has a declared safe hook ID"
            },
            {
              "id": "signing_ref_declared",
              "text": "every hook signing reference exists in `app_secrets@1`"
            },
            {
              "id": "bounded_inbound",
              "text": "body size, retention, and event count are bounded"
            },
            {
              "id": "verified_events_only",
              "text": "browser code consumes only verified events through managed status/poll/ack helpers"
            },
            {
              "id": "no_signing_secret_exposure",
              "text": "signing secrets are never embedded or returned to browser code"
            },
            {
              "id": "app_user_dependency",
              "text": "`authMode: \"app_user\"` also declares enabled `app_users@1` when used"
            }
          ]
        }
      },
      "pinnedAt": "2026-09-22T04:20:00.000Z",
      "pinnedBy": "block14-reliability-production"
    },
    {
      "instructionModuleId": "aqteron.capability.external_api_proxy@1",
      "instructionModuleVersionId": "aqteron.capability.external_api_proxy@1@0.1.0",
      "moduleKey": "aqteron.capability.external_api_proxy@1",
      "moduleKind": "capability",
      "displayName": "External API Proxy",
      "description": "Allowlisted bounded HTTPS calls with server-held authentication and SSRF protection.",
      "sourcePath": "capabilities/EXTERNAL_API_PROXY.md",
      "versionLabel": "0.1.0",
      "contentSha256": "8b7dd25ec8359daedc3e7b7567d87b322054cbda9f24f13697ef435d3e9623e7",
      "moduleMetadata": {
        "sourcePath": "capabilities/EXTERNAL_API_PROXY.md",
        "instructionId": "aqteron.capability.external_api_proxy@1"
      },
      "versionMetadata": {
        "status": "draft",
        "contract": "Aqteron PWA v1",
        "sourcePath": "capabilities/EXTERNAL_API_PROXY.md",
        "instructionSet": {
          "id": "aqteron.app-generation",
          "version": "0.2.18"
        },
        "dependencies": [
          {
            "instructionModuleId": "aqteron.capability.app_secrets@1",
            "instructionModuleVersionId": "aqteron.capability.app_secrets@1@0.1.0"
          }
        ],
        "capabilityAvailability": {
          "capabilityKey": "external_api_proxy@1",
          "registryStatus": "available",
          "runtimeStatus": "runtime_available",
          "builderSelectable": true,
          "instructionVisible": true,
          "entitlementAuthority": "aqteron_validator_runtime"
        },
        "selectionMetadata": {
          "schemaVersion": "aqteron.builder.selection_metadata.v1",
          "summary": "Allowlisted bounded HTTPS calls with server-held authentication and SSRF protection.",
          "userNeeds": [
            "call a specific approved external HTTPS API",
            "use server-held authentication for a third-party provider",
            "keep outbound network access bounded and auditable"
          ],
          "selectionSignals": [
            "the workflow explicitly depends on one or more known public API domains",
            "declared methods, body sizes, timeouts, and quotas are sufficient",
            "the provider can be called without arbitrary headers or redirects"
          ],
          "exclusions": [
            "arbitrary internet access, crawling, private/internal URLs, custom ports, raw sockets, or browser automation",
            "client-supplied Authorization/Cookie headers or absolute URLs"
          ],
          "dependencies": [
            "app_secrets@1"
          ],
          "compatibility": {
            "contracts": [
              "Aqteron PWA v1"
            ],
            "requires": [
              "app_secrets@1"
            ],
            "conflicts": []
          },
          "runtime": {
            "adapterId": "external_api_proxy@1"
          },
          "availability": {
            "instructionStatus": "draft",
            "registryStatus": "available",
            "runtimeStatus": "runtime_available",
            "builderSelectable": true,
            "instructionVisible": true,
            "entitlementAuthority": "aqteron_validator_runtime",
            "notSelectableReason": null
          }
        },
        "selfCheckMetadata": {
          "schemaVersion": "aqteron.builder.module_self_check.v1",
          "instructionModuleId": "aqteron.capability.external_api_proxy@1",
          "moduleKind": "capability",
          "required": true,
          "appliesWhenSelected": true,
          "sourceHeading": "Module self-check",
          "checks": [
            {
              "id": "declared_domain_method",
              "text": "every external API domain and HTTP method used by the app is explicitly declared"
            },
            {
              "id": "server_held_auth",
              "text": "authentication uses only declared `app_secrets@1` references"
            },
            {
              "id": "relative_request_only",
              "text": "generated code sends only domain, method, relative path, bounded query, and optional JSON body"
            },
            {
              "id": "no_client_headers_or_url",
              "text": "no absolute URL, arbitrary headers, Authorization/Cookie value, protocol, port, host override, or IP target is client supplied"
            },
            {
              "id": "bounded_network_limits",
              "text": "timeout, request bytes, response bytes, and requests-per-minute quota are declared and bounded"
            },
            {
              "id": "app_user_dependency",
              "text": "`authMode: \"app_user\"` also declares enabled `app_users@1`"
            },
            {
              "id": "managed_helper_only",
              "text": "generated code uses only the managed external API helper"
            }
          ]
        }
      },
      "pinnedAt": "2026-09-22T04:20:00.000Z",
      "pinnedBy": "block14-reliability-production"
    },
    {
      "instructionModuleId": "aqteron.capability.push_notifications@1",
      "instructionModuleVersionId": "aqteron.capability.push_notifications@1@0.1.5",
      "moduleKey": "aqteron.capability.push_notifications@1",
      "moduleKind": "capability",
      "displayName": "Aqteron Capability: push_notifications@1",
      "description": "",
      "sourcePath": "capabilities/PUSH_NOTIFICATIONS.md",
      "versionLabel": "0.1.5",
      "contentSha256": "dd8f2a4c793617b37a9afc1ab1fb9d28a515693e4ecc712cb83a594ac6304074",
      "moduleMetadata": {
        "sourcePath": "capabilities/PUSH_NOTIFICATIONS.md",
        "instructionId": "aqteron.capability.push_notifications@1"
      },
      "versionMetadata": {
        "status": "draft",
        "contract": "Aqteron PWA v1",
        "sourcePath": "capabilities/PUSH_NOTIFICATIONS.md",
        "instructionSet": {
          "id": "aqteron.app-generation",
          "version": "0.2.16"
        },
        "dependencies": [],
        "capabilityAvailability": {
          "capabilityKey": "push_notifications@1",
          "registryStatus": "available",
          "runtimeStatus": "runtime_available",
          "builderSelectable": true,
          "instructionVisible": true,
          "entitlementAuthority": "aqteron_validator_runtime"
        },
        "selectionMetadata": {
          "schemaVersion": "aqteron.builder.selection_metadata.v1",
          "summary": "Platform-managed push notification subscription and declared trigger support.",
          "userNeeds": [
            "notify users while the installed or browser PWA is closed",
            "support declared message, reminder, or shared-data alerts",
            "let users subscribe, unsubscribe, and manage notification preferences"
          ],
          "selectionSignals": [
            "user explicitly needs push or closed-app alerts",
            "notification trigger fits the supported platform contract",
            "helper-only subscription controls are sufficient"
          ],
          "exclusions": [
            "custom service workers or direct push provider calls",
            "invented send endpoints or arbitrary server triggers",
            "storing browser subscription secrets in app state"
          ],
          "dependencies": [],
          "compatibility": {
            "contracts": [
              "Aqteron PWA v1"
            ],
            "requires": [],
            "conflicts": []
          },
          "runtime": {
            "adapterId": null
          },
          "availability": {
            "instructionStatus": "draft",
            "registryStatus": "available",
            "runtimeStatus": "runtime_available",
            "builderSelectable": true,
            "instructionVisible": true,
            "entitlementAuthority": "aqteron_validator_runtime",
            "notSelectableReason": null
          }
        },
        "selfCheckMetadata": {
          "schemaVersion": "aqteron.builder.module_self_check.v1",
          "instructionModuleId": "aqteron.capability.push_notifications@1",
          "moduleKind": "capability",
          "required": true,
          "appliesWhenSelected": true,
          "sourceHeading": "Module self-check",
          "checks": [
            {
              "id": "declared_when_helper_used",
              "text": "`push_notifications@1` is declared when notifications helper is used"
            },
            {
              "id": "supported_methods_only",
              "text": "only supported helper methods are called and no `send()` exists"
            },
            {
              "id": "no_app_service_worker_or_provider",
              "text": "no application service worker or push-provider endpoint is included"
            },
            {
              "id": "identity_mode_flow",
              "text": "identity flow matches the app: with `app_users@1`, push uses the trusted app-user session and never calls `connectAccount()`; without it, legacy account linking and permission remain separate explicit user actions"
            },
            {
              "id": "no_client_recipient_identity_authority",
              "text": "no client-supplied user identity is treated as recipient ownership authority"
            },
            {
              "id": "declared_database_trigger_fields",
              "text": "triggers use declared `app_database.record.create` fields"
            },
            {
              "id": "push_create_trigger_uses_create_path",
              "text": "every `app_database.record.create` trigger record uses the `appDatabase.put` create path, including offline/deferred replay"
            },
            {
              "id": "bounded_trigger_fields",
              "text": "actor/target/click URL fields exist as bounded strings in the database schema"
            },
            {
              "id": "same_app_click_url",
              "text": "click URL is root-relative and same-app"
            },
            {
              "id": "bounded_non_private_content",
              "text": "notification title/body are bounded and do not expose private message contents"
            },
            {
              "id": "opaque_recipient_ids",
              "text": "opaque recipient IDs are not treated as secrets or modified"
            }
          ]
        }
      },
      "pinnedAt": "2026-09-22T04:20:00.000Z",
      "pinnedBy": "block14-reliability-production"
    },
    {
      "instructionModuleId": "aqteron.capability.realtime_events@1",
      "instructionModuleVersionId": "aqteron.capability.realtime_events@1@0.1.1",
      "moduleKey": "aqteron.capability.realtime_events@1",
      "moduleKind": "capability",
      "displayName": "Realtime Events",
      "description": "Bounded app/user-scoped realtime update signals.",
      "sourcePath": "capabilities/REALTIME_EVENTS.md",
      "versionLabel": "0.1.1",
      "contentSha256": "6c1d3c59037e07d7bb4228d993f6a4ebecdf04e29d2680e008993e2c63b976e5",
      "moduleMetadata": {
        "sourcePath": "capabilities/REALTIME_EVENTS.md",
        "instructionId": "aqteron.capability.realtime_events@1"
      },
      "versionMetadata": {
        "status": "draft",
        "contract": "Aqteron PWA v1",
        "sourcePath": "capabilities/REALTIME_EVENTS.md",
        "instructionSet": {
          "id": "aqteron.app-generation",
          "version": "0.2.20"
        },
        "dependencies": [],
        "capabilityAvailability": {
          "capabilityKey": "realtime_events@1",
          "registryStatus": "available",
          "runtimeStatus": "runtime_available",
          "builderSelectable": true,
          "instructionVisible": true,
          "entitlementAuthority": "aqteron_validator_runtime"
        },
        "selectionMetadata": {
          "schemaVersion": "aqteron.builder.selection_metadata.v1",
          "summary": "Bounded app/user-scoped live update signals with reconnect and replay.",
          "userNeeds": [
            "update an already-open app quickly when durable shared state changes",
            "show message/status/read-state/presence changes without manual refresh",
            "replay a bounded window of missed live update signals after reconnect"
          ],
          "selectionSignals": [
            "the workflow has multi-tab, multi-device, or multi-user live updates",
            "durable records remain in app_database@1 while realtime only signals changes",
            "bounded long-poll transport with replay is sufficient"
          ],
          "exclusions": [
            "durable business-data history or unbounded event logs",
            "custom WebSocket/SSE servers or arbitrary backend realtime infrastructure",
            "large payloads, files, credentials, secrets, or raw session/user identity transport"
          ],
          "dependencies": [],
          "compatibility": {
            "contracts": [
              "Aqteron PWA v1"
            ],
            "requires": [],
            "conflicts": []
          },
          "runtime": {
            "adapterId": "realtime_events@1"
          },
          "availability": {
            "instructionStatus": "draft",
            "registryStatus": "available",
            "runtimeStatus": "runtime_available",
            "builderSelectable": true,
            "instructionVisible": true,
            "entitlementAuthority": "aqteron_validator_runtime",
            "notSelectableReason": null
          }
        },
        "selfCheckMetadata": {
          "schemaVersion": "aqteron.builder.module_self_check.v1",
          "instructionModuleId": "aqteron.capability.realtime_events@1",
          "moduleKind": "capability",
          "required": true,
          "appliesWhenSelected": true,
          "sourceHeading": "Module self-check",
          "checks": [
            {
              "id": "declared_when_helper_used",
              "text": "`realtime_events@1` is declared whenever `realtimeEvents` is used"
            },
            {
              "id": "supported_methods_only",
              "text": "only the exact managed `status`, `publish`, `poll`, and `subscribe` helper methods are used"
            },
            {
              "id": "channels_types_declared",
              "text": "every used channel and event type is declared"
            },
            {
              "id": "bounded_limits",
              "text": "each channel has bounded retention, event count, and payload size within the exact platform limits"
            },
            {
              "id": "app_user_dependency",
              "text": "`app_user` channels also declare enabled `app_users@1`"
            },
            {
              "id": "no_client_authority",
              "text": "no client-supplied app/user/subject/session/storage identifier is used as authorization authority"
            },
            {
              "id": "durable_data_separate",
              "text": "durable business records remain in `app_database@1` or another appropriate durable capability"
            },
            {
              "id": "cursor_reset_refreshes",
              "text": "cursor reset causes an authoritative state refresh instead of guessing missing events"
            },
            {
              "id": "bounded_subscribe_retry",
              "text": "subscribe retry uses a bounded exponential backoff with a single in-flight poll"
            },
            {
              "id": "no_reconnect_amplification",
              "text": "reconnect preserves the cursor and does not republish replay/presence events automatically"
            },
            {
              "id": "presence_ephemeral",
              "text": "presence is treated only as an ephemeral hint"
            },
            {
              "id": "no_sensitive_payloads",
              "text": "realtime payloads contain no secrets, credentials, raw session tokens, files, or large/private record bodies"
            }
          ]
        }
      },
      "pinnedAt": "2026-09-22T04:20:00.000Z",
      "pinnedBy": "block14-reliability-production"
    },
    {
      "instructionModuleId": "aqteron.capability.web_parser@1",
      "instructionModuleVersionId": "aqteron.capability.web_parser@1@0.1.4",
      "moduleKey": "aqteron.capability.web_parser@1",
      "moduleKind": "capability",
      "displayName": "Aqteron Capability: web_parser@1",
      "description": "",
      "sourcePath": "capabilities/WEB_PARSER.md",
      "versionLabel": "0.1.4",
      "contentSha256": "3360d11b8d7fd6124694cd83d606eccb68bafe2f697dba915fa655f12c36661a",
      "moduleMetadata": {
        "sourcePath": "capabilities/WEB_PARSER.md",
        "instructionId": "aqteron.capability.web_parser@1"
      },
      "versionMetadata": {
        "status": "draft",
        "contract": "Aqteron PWA v1",
        "sourcePath": "capabilities/WEB_PARSER.md",
        "instructionSet": {
          "id": "aqteron.app-generation",
          "version": "0.2.14"
        },
        "dependencies": [],
        "capabilityAvailability": {
          "capabilityKey": "web_parser@1",
          "registryStatus": "available",
          "runtimeStatus": "runtime_available",
          "builderSelectable": true,
          "instructionVisible": true,
          "entitlementAuthority": "aqteron_validator_runtime"
        },
        "selectionMetadata": {
          "schemaVersion": "aqteron.builder.selection_metadata.v1",
          "summary": "Bounded readable-text parsing for explicitly approved public domains.",
          "userNeeds": [
            "read sanitized text from approved public HTTP(S) pages",
            "extract readable text from a specific public URL",
            "use public web text inside an Aqteron workflow"
          ],
          "selectionSignals": [
            "live generation context marks this module usable for the account",
            "source pages are public, readable, and approved",
            "readable_text output is sufficient"
          ],
          "exclusions": [
            "login-only, private, internal, localhost, or metadata URLs",
            "broad crawling, screenshots, binary downloads, raw HTML execution, or browser automation"
          ],
          "dependencies": [],
          "compatibility": {
            "contracts": [
              "Aqteron PWA v1"
            ],
            "requires": [],
            "conflicts": []
          },
          "runtime": {
            "adapterId": "web_parser@1"
          },
          "availability": {
            "instructionStatus": "draft",
            "registryStatus": "available",
            "runtimeStatus": "runtime_available",
            "builderSelectable": true,
            "instructionVisible": true,
            "entitlementAuthority": "aqteron_validator_runtime",
            "notSelectableReason": null
          }
        },
        "selfCheckMetadata": {
          "schemaVersion": "aqteron.builder.module_self_check.v1",
          "instructionModuleId": "aqteron.capability.web_parser@1",
          "moduleKind": "capability",
          "required": true,
          "appliesWhenSelected": true,
          "sourceHeading": "Module self-check",
          "checks": [
            {
              "id": "workflow_needs_public_text",
              "text": "the user workflow genuinely needs public readable text"
            },
            {
              "id": "requested_domains_declared",
              "text": "every requested domain is explicitly declared"
            },
            {
              "id": "readable_text_only",
              "text": "only `readable_text` is requested"
            },
            {
              "id": "no_login_or_auth_forwarding",
              "text": "no login/session/cookie/Auth forwarding is attempted"
            },
            {
              "id": "no_private_targets",
              "text": "no private/internal/localhost/IP target is accepted"
            },
            {
              "id": "no_direct_scraping",
              "text": "no direct cross-origin scraping/headless crawling is implemented"
            },
            {
              "id": "declaration_request_agree",
              "text": "capability declaration and request URL agree"
            },
            {
              "id": "platform_errors_user_facing",
              "text": "platform errors are shown in user-facing form"
            }
          ]
        }
      },
      "pinnedAt": "2026-09-22T04:20:00.000Z",
      "pinnedBy": "block14-reliability-production"
    },
    {
      "instructionModuleId": "aqteron.capability.webrtc_signaling@1",
      "instructionModuleVersionId": "aqteron.capability.webrtc_signaling@1@0.1.6",
      "moduleKey": "aqteron.capability.webrtc_signaling@1",
      "moduleKind": "capability",
      "displayName": "Aqteron Capability: webrtc_signaling@1",
      "description": "",
      "sourcePath": "capabilities/WEBRTC_SIGNALING.md",
      "versionLabel": "0.1.6",
      "contentSha256": "69d9a7cd353062540860ed9893da8d662f36a0887771d5008b66611a21f3edc0",
      "moduleMetadata": {
        "sourcePath": "capabilities/WEBRTC_SIGNALING.md",
        "instructionId": "aqteron.capability.webrtc_signaling@1"
      },
      "versionMetadata": {
        "status": "draft",
        "contract": "Aqteron PWA v1",
        "sourcePath": "capabilities/WEBRTC_SIGNALING.md",
        "instructionSet": {
          "id": "aqteron.app-generation",
          "version": "0.2.20"
        },
        "dependencies": [],
        "capabilityAvailability": {
          "capabilityKey": "webrtc_signaling@1",
          "registryStatus": "available",
          "runtimeStatus": "runtime_available",
          "builderSelectable": true,
          "instructionVisible": true,
          "entitlementAuthority": "aqteron_validator_runtime"
        },
        "selectionMetadata": {
          "schemaVersion": "aqteron.builder.selection_metadata.v1",
          "summary": "Short-lived app-scoped signaling for browser peer-to-peer WebRTC setup.",
          "userNeeds": [
            "coordinate browser peer-to-peer audio, video, or data channel setup",
            "exchange short-lived WebRTC signaling messages",
            "support real-time peer connection workflows"
          ],
          "selectionSignals": [
            "live generation context marks this module usable for the account",
            "application needs WebRTC signaling with platform-managed relay fallback when direct connectivity fails",
            "short-lived helper-mediated signaling and managed ICE credentials are sufficient"
          ],
          "exclusions": [
            "media recording, SFU/media processing, custom TURN/STUN credential management, or persistent chat storage",
            "storing SDP or ICE payloads in app_database@1"
          ],
          "dependencies": [],
          "compatibility": {
            "contracts": [
              "Aqteron PWA v1"
            ],
            "requires": [],
            "conflicts": []
          },
          "runtime": {
            "adapterId": "webrtc_signaling@1"
          },
          "availability": {
            "instructionStatus": "draft",
            "registryStatus": "available",
            "runtimeStatus": "runtime_available",
            "builderSelectable": true,
            "instructionVisible": true,
            "entitlementAuthority": "aqteron_validator_runtime",
            "notSelectableReason": null
          }
        },
        "selfCheckMetadata": {
          "schemaVersion": "aqteron.builder.module_self_check.v1",
          "instructionModuleId": "aqteron.capability.webrtc_signaling@1",
          "moduleKind": "capability",
          "required": true,
          "appliesWhenSelected": true,
          "sourceHeading": "Module self-check",
          "checks": [
            {
              "id": "declared_when_helper_used",
              "text": "the capability is declared if signaling helper is used"
            },
            {
              "id": "signaling_not_database_persisted",
              "text": "signaling data is not persisted in `app_database@1`"
            },
            {
              "id": "no_custom_signaling_route",
              "text": "no private/custom signaling server route is invented"
            },
            {
              "id": "bounded_payload_and_ttl",
              "text": "payload size and TTL are bounded"
            },
            {
              "id": "managed_turn_media_boundary",
              "text": "media remains browser WebRTC traffic; managed TURN is only an encrypted-packet relay and is not recording or media processing"
            },
            {
              "id": "managed_turn_helper_only",
              "text": "ICE configuration comes only from the platform helper; no hardcoded relay credentials or routes are embedded"
            },
            {
              "id": "managed_turn_ephemeral",
              "text": "short-lived managed TURN credentials are never persisted and are refreshed for new/recovered calls"
            },
            {
              "id": "participant_resume_bounded",
              "text": "participant recovery uses only the server-issued volatile `resumeToken` and bounded `participant.resume` retries"
            },
            {
              "id": "app_user_resume_continuity",
              "text": "app-user-bound participants cannot resume as a different trusted app user"
            },
            {
              "id": "no_blind_signal_retry",
              "text": "non-idempotent signaling sends are not blindly retried"
            },
            {
              "id": "recovery_cursor_continuity",
              "text": "recovery continues from the last signaling sequence rather than replaying from zero"
            },
            {
              "id": "visible_failure_states",
              "text": "call failure and unsupported-environment states are shown to the user"
            }
          ]
        }
      },
      "pinnedAt": "2026-09-22T04:20:00.000Z",
      "pinnedBy": "block14-reliability-production"
    },
    {
      "instructionModuleId": "aqteron.final-check.pwa-v1",
      "instructionModuleVersionId": "aqteron.final-check.pwa-v1@0.2.2",
      "moduleKey": "aqteron.final-check.pwa-v1",
      "moduleKind": "final_check",
      "displayName": "Aqteron Final Check",
      "description": "",
      "sourcePath": "FINAL_CHECK.md",
      "versionLabel": "0.2.2",
      "contentSha256": "0d6797c3c4324694a36e8e9f61e8f4c7351ed97a4ea683e1455df23d58598d77",
      "moduleMetadata": {
        "sourcePath": "FINAL_CHECK.md",
        "instructionId": "aqteron.final-check.pwa-v1"
      },
      "versionMetadata": {
        "status": "draft",
        "contract": "Aqteron PWA v1",
        "sourcePath": "FINAL_CHECK.md",
        "instructionSet": {
          "id": "aqteron.app-generation",
          "version": "0.2.2"
        },
        "dependencies": []
      },
      "pinnedAt": "2026-09-22T04:20:00.000Z",
      "pinnedBy": "block14-reliability-production"
    },
    {
      "instructionModuleId": "aqteron.final-response.user-facing-v1",
      "instructionModuleVersionId": "aqteron.final-response.user-facing-v1@0.1.1",
      "moduleKey": "aqteron.final-response.user-facing-v1",
      "moduleKind": "final_response",
      "displayName": "Aqteron User-Facing Final Response",
      "description": "",
      "sourcePath": "FINAL_RESPONSE.md",
      "versionLabel": "0.1.1",
      "contentSha256": "9784bf20ba0c313a559375b12d7fe83c921ae7ef8122cbf448b008a79a93d31a",
      "moduleMetadata": {
        "sourcePath": "FINAL_RESPONSE.md",
        "instructionId": "aqteron.final-response.user-facing-v1"
      },
      "versionMetadata": {
        "status": "draft",
        "contract": "Aqteron PWA v1",
        "sourcePath": "FINAL_RESPONSE.md",
        "instructionSet": {
          "id": "aqteron.app-generation",
          "version": "0.2.13"
        },
        "dependencies": []
      },
      "pinnedAt": "2026-09-22T04:20:00.000Z",
      "pinnedBy": "block14-reliability-production"
    },
    {
      "instructionModuleId": "aqteron.package.pwa-v1",
      "instructionModuleVersionId": "aqteron.package.pwa-v1@0.1.3",
      "moduleKey": "aqteron.package.pwa-v1",
      "moduleKind": "package",
      "displayName": "Aqteron Package Contract",
      "description": "",
      "sourcePath": "PACKAGE.md",
      "versionLabel": "0.1.3",
      "contentSha256": "8fdd25c656a7dd2a171660eb7bbb419bebf0835b72b00c10158f06660abe16f1",
      "moduleMetadata": {
        "sourcePath": "PACKAGE.md",
        "instructionId": "aqteron.package.pwa-v1"
      },
      "versionMetadata": {
        "status": "draft",
        "contract": "Aqteron PWA v1",
        "sourcePath": "PACKAGE.md",
        "instructionSet": {
          "id": "aqteron.app-generation",
          "version": "0.2.4"
        },
        "dependencies": []
      },
      "pinnedAt": "2026-09-22T04:20:00.000Z",
      "pinnedBy": "block14-reliability-production"
    },
    {
      "instructionModuleId": "aqteron.type.app",
      "instructionModuleVersionId": "aqteron.type.app@0.1.1",
      "moduleKey": "aqteron.type.app",
      "moduleKind": "type",
      "displayName": "Aqteron Product Type: Application",
      "description": "",
      "sourcePath": "types/APP.md",
      "versionLabel": "0.1.1",
      "contentSha256": "a4d220de4a687403f00c74f3a2658885f035c400b3bbb5bd869c9b074b75ca03",
      "moduleMetadata": {
        "sourcePath": "types/APP.md",
        "instructionId": "aqteron.type.app"
      },
      "versionMetadata": {
        "status": "draft",
        "contract": "Aqteron PWA v1",
        "sourcePath": "types/APP.md",
        "instructionSet": {
          "id": "aqteron.app-generation",
          "version": "0.2.2"
        },
        "dependencies": [],
        "selectionMetadata": {
          "schemaVersion": "aqteron.builder.selection_metadata.v1",
          "summary": "Focused record or workflow application for repeated personal or business tasks.",
          "userNeeds": [
            "track records or ongoing state",
            "organize repeated workflows",
            "manage personal or business data"
          ],
          "selectionSignals": [
            "records need create/view/edit/delete behavior",
            "workflow spans multiple steps or screens",
            "saved state is central to the user value"
          ],
          "exclusions": [
            "one-off calculator, converter, validator, or generator",
            "primarily informational or promotional website",
            "playable game-first request"
          ],
          "dependencies": [],
          "compatibility": {
            "contracts": [
              "Aqteron PWA v1"
            ],
            "requires": [],
            "conflicts": []
          },
          "runtime": {
            "adapterId": null
          },
          "availability": {
            "instructionStatus": "draft",
            "registryStatus": null,
            "runtimeStatus": null,
            "builderSelectable": true,
            "instructionVisible": true,
            "entitlementAuthority": null,
            "notSelectableReason": null
          }
        }
      },
      "pinnedAt": "2026-09-22T04:20:00.000Z",
      "pinnedBy": "block14-reliability-production"
    },
    {
      "instructionModuleId": "aqteron.type.game",
      "instructionModuleVersionId": "aqteron.type.game@0.1.1",
      "moduleKey": "aqteron.type.game",
      "moduleKind": "type",
      "displayName": "Aqteron Product Type: Game",
      "description": "",
      "sourcePath": "types/GAME.md",
      "versionLabel": "0.1.1",
      "contentSha256": "fad98ade2dfb39851e044dc3c461982c3991481aa99304a24e84309d036fff8f",
      "moduleMetadata": {
        "sourcePath": "types/GAME.md",
        "instructionId": "aqteron.type.game"
      },
      "versionMetadata": {
        "status": "draft",
        "contract": "Aqteron PWA v1",
        "sourcePath": "types/GAME.md",
        "instructionSet": {
          "id": "aqteron.app-generation",
          "version": "0.2.2"
        },
        "dependencies": [],
        "selectionMetadata": {
          "schemaVersion": "aqteron.builder.selection_metadata.v1",
          "summary": "Playable browser game with a complete objective, loop, controls, and feedback.",
          "userNeeds": [
            "play a browser game",
            "support scoring, levels, turns, challenge, or replay",
            "create an interactive entertainment experience"
          ],
          "selectionSignals": [
            "primary value is gameplay",
            "rules, controls, win/loss, score, or progression are required",
            "first screen should start or explain play"
          ],
          "exclusions": [
            "business or personal record workflow",
            "one-off productivity utility",
            "informational or promotional website"
          ],
          "dependencies": [],
          "compatibility": {
            "contracts": [
              "Aqteron PWA v1"
            ],
            "requires": [],
            "conflicts": []
          },
          "runtime": {
            "adapterId": null
          },
          "availability": {
            "instructionStatus": "draft",
            "registryStatus": null,
            "runtimeStatus": null,
            "builderSelectable": true,
            "instructionVisible": true,
            "entitlementAuthority": null,
            "notSelectableReason": null
          }
        }
      },
      "pinnedAt": "2026-09-22T04:20:00.000Z",
      "pinnedBy": "block14-reliability-production"
    },
    {
      "instructionModuleId": "aqteron.type.tool",
      "instructionModuleVersionId": "aqteron.type.tool@0.1.1",
      "moduleKey": "aqteron.type.tool",
      "moduleKind": "type",
      "displayName": "Aqteron Product Type: Tool",
      "description": "",
      "sourcePath": "types/TOOL.md",
      "versionLabel": "0.1.1",
      "contentSha256": "542e780b53c5b6cbcff55fa71d3b8661d0089364b5e1a2359a6640b62da3f008",
      "moduleMetadata": {
        "sourcePath": "types/TOOL.md",
        "instructionId": "aqteron.type.tool"
      },
      "versionMetadata": {
        "status": "draft",
        "contract": "Aqteron PWA v1",
        "sourcePath": "types/TOOL.md",
        "instructionSet": {
          "id": "aqteron.app-generation",
          "version": "0.2.2"
        },
        "dependencies": [],
        "selectionMetadata": {
          "schemaVersion": "aqteron.builder.selection_metadata.v1",
          "summary": "Direct task-first utility for a narrow input-action-result workflow.",
          "userNeeds": [
            "calculate, convert, generate, analyze, validate, format, or plan",
            "complete a narrow task with clear inputs and outputs",
            "reuse a compact work instrument"
          ],
          "selectionSignals": [
            "single primary action produces the result",
            "inputs, assumptions, validation, and output are the main workflow",
            "dashboard, account, or record lifecycle is not central"
          ],
          "exclusions": [
            "broad multi-record application",
            "marketing or content website",
            "playable game"
          ],
          "dependencies": [],
          "compatibility": {
            "contracts": [
              "Aqteron PWA v1"
            ],
            "requires": [],
            "conflicts": []
          },
          "runtime": {
            "adapterId": null
          },
          "availability": {
            "instructionStatus": "draft",
            "registryStatus": null,
            "runtimeStatus": null,
            "builderSelectable": true,
            "instructionVisible": true,
            "entitlementAuthority": null,
            "notSelectableReason": null
          }
        }
      },
      "pinnedAt": "2026-09-22T04:20:00.000Z",
      "pinnedBy": "block14-reliability-production"
    },
    {
      "instructionModuleId": "aqteron.type.website",
      "instructionModuleVersionId": "aqteron.type.website@0.1.1",
      "moduleKey": "aqteron.type.website",
      "moduleKind": "type",
      "displayName": "Aqteron Product Type: Website",
      "description": "",
      "sourcePath": "types/WEBSITE.md",
      "versionLabel": "0.1.1",
      "contentSha256": "278a6fed8766375fe579f692438e7d0c88d44b192f09caff734a5fcd3e580c5c",
      "moduleMetadata": {
        "sourcePath": "types/WEBSITE.md",
        "instructionId": "aqteron.type.website"
      },
      "versionMetadata": {
        "status": "draft",
        "contract": "Aqteron PWA v1",
        "sourcePath": "types/WEBSITE.md",
        "instructionSet": {
          "id": "aqteron.app-generation",
          "version": "0.2.2"
        },
        "dependencies": [],
        "selectionMetadata": {
          "schemaVersion": "aqteron.builder.selection_metadata.v1",
          "summary": "Publishable informational, promotional, portfolio, catalogue, or company website.",
          "userNeeds": [
            "present information, brand, offer, work, catalogue, or content",
            "guide visitors to contact, buy, book, learn, or explore",
            "publish a multi-section or multi-page site"
          ],
          "selectionSignals": [
            "visitor communication is the main goal",
            "sections such as overview, proof, services, pricing, FAQ, or contact are useful",
            "content hierarchy and calls to action matter more than record management"
          ],
          "exclusions": [
            "repeated record-based application",
            "single-purpose calculator or generator",
            "playable game"
          ],
          "dependencies": [],
          "compatibility": {
            "contracts": [
              "Aqteron PWA v1"
            ],
            "requires": [],
            "conflicts": []
          },
          "runtime": {
            "adapterId": null
          },
          "availability": {
            "instructionStatus": "draft",
            "registryStatus": null,
            "runtimeStatus": null,
            "builderSelectable": true,
            "instructionVisible": true,
            "entitlementAuthority": null,
            "notSelectableReason": null
          }
        }
      },
      "pinnedAt": "2026-09-22T04:20:00.000Z",
      "pinnedBy": "block14-reliability-production"
    }
  ],
  "capabilityRegistry": [
    {
      "capabilityKey": "ai_bridge@1",
      "instructionModuleId": null,
      "instructionModuleVersionId": null,
      "registryStatus": "disabled",
      "displayName": "AI Bridge",
      "summary": "Disabled scaffold capability; unavailable in current production.",
      "metadataJson": "{\"runtimeStatus\":\"disabled_scaffold\",\"builderSelectable\":false,\"instructionVisible\":false,\"entitlementAuthority\":\"aqteron_validator_runtime\",\"presentation\":{\"locales\":{\"en\":{\"name\":\"AI Bridge\",\"summary\":\"Disabled scaffold capability; unavailable in current production.\"},\"fr\":{\"name\":\"Passerelle IA\",\"summary\":\"Capacité préparatoire désactivée, indisponible dans la production actuelle.\"},\"ru\":{\"name\":\"Шлюз ИИ\",\"summary\":\"Отключённая заготовка возможности; недоступна в текущей production-среде.\"}}},\"notSelectableReason\":\"Disabled scaffold capability; unavailable in current production.\"}",
      "metadata": {
        "runtimeStatus": "disabled_scaffold",
        "builderSelectable": false,
        "instructionVisible": false,
        "entitlementAuthority": "aqteron_validator_runtime",
        "presentation": {
          "locales": {
            "en": {
              "name": "AI Bridge",
              "summary": "Disabled scaffold capability; unavailable in current production."
            },
            "fr": {
              "name": "Passerelle IA",
              "summary": "Capacité préparatoire désactivée, indisponible dans la production actuelle."
            },
            "ru": {
              "name": "Шлюз ИИ",
              "summary": "Отключённая заготовка возможности; недоступна в текущей production-среде."
            }
          }
        },
        "notSelectableReason": "Disabled scaffold capability; unavailable in current production."
      },
      "createdAt": "2026-09-16T05:00:00.000Z",
      "updatedAt": "2026-09-16T05:00:00.000Z"
    },
    {
      "capabilityKey": "app_database@1",
      "instructionModuleId": "aqteron.capability.app_database@1",
      "instructionModuleVersionId": "aqteron.capability.app_database@1@0.1.5",
      "registryStatus": "available",
      "displayName": "App Database",
      "summary": "App-scoped JSON record storage for shared or cross-device persistence.",
      "metadataJson": "{\"runtimeStatus\":\"runtime_available\",\"builderSelectable\":true,\"instructionVisible\":true,\"entitlementAuthority\":\"aqteron_validator_runtime\",\"presentation\":{\"locales\":{\"en\":{\"name\":\"App Database\",\"summary\":\"App-scoped JSON record storage for shared or cross-device persistence.\"},\"fr\":{\"name\":\"Base de données de l'application\",\"summary\":\"Stockage de documents JSON propre à l'application pour une persistance partagée ou multi-appareil.\"},\"ru\":{\"name\":\"База данных приложения\",\"summary\":\"Хранилище JSON-записей приложения для общего доступа и синхронизации между устройствами.\"}}},\"sourcePath\":\"capabilities/APP_DATABASE.md\",\"selectionMetadata\":{\"schemaVersion\":\"aqteron.builder.selection_metadata.v1\",\"summary\":\"App-scoped JSON record storage for shared or cross-device persistence.\",\"userNeeds\":[\"persist structured records beyond one browser or install\",\"share app-scoped records across linked users or devices\",\"store bounded server-side JSON records\"],\"selectionSignals\":[\"localStorage or IndexedDB is insufficient\",\"records must survive reinstall or device changes\",\"multiple users or devices need the same app data\"],\"exclusions\":[\"file, image, document, or attachment storage\",\"raw SQL or arbitrary backend database access\",\"secrets, credentials, passwords, tokens, or private keys\"],\"dependencies\":[],\"compatibility\":{\"contracts\":[\"Aqteron PWA v1\"],\"requires\":[],\"conflicts\":[]},\"runtime\":{\"adapterId\":\"app_database@1\"},\"availability\":{\"instructionStatus\":\"draft\",\"registryStatus\":\"available\",\"runtimeStatus\":\"runtime_available\",\"builderSelectable\":true,\"instructionVisible\":true,\"entitlementAuthority\":\"aqteron_validator_runtime\",\"notSelectableReason\":null}},\"selfCheckMetadata\":{\"schemaVersion\":\"aqteron.builder.module_self_check.v1\",\"instructionModuleId\":\"aqteron.capability.app_database@1\",\"moduleKind\":\"capability\",\"required\":true,\"appliesWhenSelected\":true,\"sourceHeading\":\"Module self-check\",\"checks\":[{\"id\":\"declared_when_helper_used\",\"text\":\"capability is declared when JavaScript uses `appDatabase`\"},{\"id\":\"used_collections_declared\",\"text\":\"every used collection is declared\"},{\"id\":\"schema_keys_match\",\"text\":\"schema and JS keys are identical lower_snake_case ASCII\"},{\"id\":\"no_undeclared_fields\",\"text\":\"no undeclared extra fields are written\"},{\"id\":\"new_record_uses_put\",\"text\":\"every new logical record uses `put` with declared `record.create`\"},{\"id\":\"existing_record_uses_set\",\"text\":\"every existing logical record update uses `set` with declared `record.update`\"},{\"id\":\"offline_replay_preserves_intent\",\"text\":\"offline/deferred replay preserves `put` versus `set` operation intent\"},{\"id\":\"bounded_list_limit\",\"text\":\"every `list` call has an explicit numeric limit from 1 to 100\"},{\"id\":\"db_list_limit_not_record_quota\",\"text\":\"a `list` retrieval limit is not treated as the collection `maxRecords` quota\"},{\"id\":\"no_raw_secrets\",\"text\":\"no raw secrets are persisted\"},{\"id\":\"no_private_database_routes\",\"text\":\"no direct/private database routes or raw SQL are used\"},{\"id\":\"app_user_server_authority\",\"text\":\"when `authMode: \\\"app_user\\\"` is selected, `app_users@1` is enabled and authorization comes only from the trusted server-resolved app-user session\"},{\"id\":\"no_client_identity_or_row_privacy_claim\",\"text\":\"no client-supplied user identity is treated as authority and no row-level privacy is claimed from `authMode` alone\"},{\"id\":\"user_readable_errors\",\"text\":\"capability failures produce user-readable UI errors\"}]}}",
      "metadata": {
        "runtimeStatus": "runtime_available",
        "builderSelectable": true,
        "instructionVisible": true,
        "entitlementAuthority": "aqteron_validator_runtime",
        "presentation": {
          "locales": {
            "en": {
              "name": "App Database",
              "summary": "App-scoped JSON record storage for shared or cross-device persistence."
            },
            "fr": {
              "name": "Base de données de l'application",
              "summary": "Stockage de documents JSON propre à l'application pour une persistance partagée ou multi-appareil."
            },
            "ru": {
              "name": "База данных приложения",
              "summary": "Хранилище JSON-записей приложения для общего доступа и синхронизации между устройствами."
            }
          }
        },
        "sourcePath": "capabilities/APP_DATABASE.md",
        "selectionMetadata": {
          "schemaVersion": "aqteron.builder.selection_metadata.v1",
          "summary": "App-scoped JSON record storage for shared or cross-device persistence.",
          "userNeeds": [
            "persist structured records beyond one browser or install",
            "share app-scoped records across linked users or devices",
            "store bounded server-side JSON records"
          ],
          "selectionSignals": [
            "localStorage or IndexedDB is insufficient",
            "records must survive reinstall or device changes",
            "multiple users or devices need the same app data"
          ],
          "exclusions": [
            "file, image, document, or attachment storage",
            "raw SQL or arbitrary backend database access",
            "secrets, credentials, passwords, tokens, or private keys"
          ],
          "dependencies": [],
          "compatibility": {
            "contracts": [
              "Aqteron PWA v1"
            ],
            "requires": [],
            "conflicts": []
          },
          "runtime": {
            "adapterId": "app_database@1"
          },
          "availability": {
            "instructionStatus": "draft",
            "registryStatus": "available",
            "runtimeStatus": "runtime_available",
            "builderSelectable": true,
            "instructionVisible": true,
            "entitlementAuthority": "aqteron_validator_runtime",
            "notSelectableReason": null
          }
        },
        "selfCheckMetadata": {
          "schemaVersion": "aqteron.builder.module_self_check.v1",
          "instructionModuleId": "aqteron.capability.app_database@1",
          "moduleKind": "capability",
          "required": true,
          "appliesWhenSelected": true,
          "sourceHeading": "Module self-check",
          "checks": [
            {
              "id": "declared_when_helper_used",
              "text": "capability is declared when JavaScript uses `appDatabase`"
            },
            {
              "id": "used_collections_declared",
              "text": "every used collection is declared"
            },
            {
              "id": "schema_keys_match",
              "text": "schema and JS keys are identical lower_snake_case ASCII"
            },
            {
              "id": "no_undeclared_fields",
              "text": "no undeclared extra fields are written"
            },
            {
              "id": "new_record_uses_put",
              "text": "every new logical record uses `put` with declared `record.create`"
            },
            {
              "id": "existing_record_uses_set",
              "text": "every existing logical record update uses `set` with declared `record.update`"
            },
            {
              "id": "offline_replay_preserves_intent",
              "text": "offline/deferred replay preserves `put` versus `set` operation intent"
            },
            {
              "id": "bounded_list_limit",
              "text": "every `list` call has an explicit numeric limit from 1 to 100"
            },
            {
              "id": "db_list_limit_not_record_quota",
              "text": "a `list` retrieval limit is not treated as the collection `maxRecords` quota"
            },
            {
              "id": "no_raw_secrets",
              "text": "no raw secrets are persisted"
            },
            {
              "id": "no_private_database_routes",
              "text": "no direct/private database routes or raw SQL are used"
            },
            {
              "id": "app_user_server_authority",
              "text": "when `authMode: \"app_user\"` is selected, `app_users@1` is enabled and authorization comes only from the trusted server-resolved app-user session"
            },
            {
              "id": "no_client_identity_or_row_privacy_claim",
              "text": "no client-supplied user identity is treated as authority and no row-level privacy is claimed from `authMode` alone"
            },
            {
              "id": "user_readable_errors",
              "text": "capability failures produce user-readable UI errors"
            }
          ]
        }
      },
      "createdAt": "2026-09-16T05:00:00.000Z",
      "updatedAt": "2026-09-21T05:10:00.000Z"
    },
    {
      "capabilityKey": "app_files@1",
      "instructionModuleId": "aqteron.capability.app_files@1",
      "instructionModuleVersionId": "aqteron.capability.app_files@1@0.3.1",
      "registryStatus": "available",
      "displayName": "App Files",
      "summary": "Guarded private file storage for entitled applications when canonical readiness controls pass.",
      "metadataJson": "{\"runtimeStatus\":\"runtime_available\",\"builderSelectable\":true,\"instructionVisible\":true,\"entitlementAuthority\":\"aqteron_validator_runtime\",\"presentation\":{\"locales\":{\"en\":{\"name\":\"App Files\",\"summary\":\"Guarded private file storage for entitled applications when canonical readiness controls pass.\"},\"fr\":{\"name\":\"Fichiers de l'application\",\"summary\":\"Stockage de fichiers privés protégé pour les applications autorisées lorsque les contrôles de disponibilité canoniques réussissent.\"},\"ru\":{\"name\":\"Файлы приложения\",\"summary\":\"Защищённое приватное хранилище файлов для приложений с правом доступа при успешной канонической проверке готовности.\"}}},\"sourcePath\":\"capabilities/APP_FILES.md\",\"selectionMetadata\":{\"schemaVersion\":\"aqteron.builder.selection_metadata.v1\",\"summary\":\"Guarded private file storage for entitled applications when canonical readiness controls pass.\",\"userNeeds\":[\"store user files, attachments, images, documents, imports, or exports\",\"keep private application-scoped files in managed storage\",\"associate files with app workflows\"],\"selectionSignals\":[\"managed private files are required and server-side entitlement is available\",\"files must persist outside local browser storage\",\"workflow references uploaded or generated files\"],\"exclusions\":[\"workflows that can remain entirely in local browser storage\",\"public hosting or public URL generation\",\"shared-drive behavior across unrelated apps or users\",\"structured JSON record storage without files\"],\"dependencies\":[],\"compatibility\":{\"contracts\":[\"Aqteron PWA v1\"],\"requires\":[],\"conflicts\":[]},\"runtime\":{\"adapterId\":\"app_files@1\"},\"availability\":{\"instructionStatus\":\"activation_candidate\",\"registryStatus\":\"available\",\"runtimeStatus\":\"runtime_available\",\"builderSelectable\":true,\"instructionVisible\":true,\"entitlementAuthority\":\"aqteron_validator_runtime\",\"notSelectableReason\":null}},\"selfCheckMetadata\":{\"schemaVersion\":\"aqteron.builder.module_self_check.v1\",\"instructionModuleId\":\"aqteron.capability.app_files@1\",\"moduleKind\":\"capability\",\"required\":true,\"appliesWhenSelected\":true,\"sourceHeading\":\"Module self-check\",\"checks\":[{\"id\":\"declared_when_helper_used\",\"text\":\"capability is declared if `appFiles` is used\"},{\"id\":\"only_prompt2app_helper\",\"text\":\"only the exact `window.Prompt2App.appFiles` methods above are used\"},{\"id\":\"subject_mode_identity_matches\",\"text\":\"identity handling matches the declared subject mode: `app_user` requires trusted app-local sign-in, `app` does not account-link, and only legacy no-`subjectMode` declarations may call `connectAccount()`\"},{\"id\":\"no_client_file_identity_authority\",\"text\":\"no client-provided user/subject identifier is used as file authorization authority\"},{\"id\":\"used_buckets_declared_private\",\"text\":\"every used bucket is declared and private\"},{\"id\":\"file_quota_dimensions_coherent\",\"text\":\"MIME types are bounded and `maxFileSizeBytes`, `maxTotalBytes`, and `maxFiles` are validated as separate dimensions within their exact ceilings\"},{\"id\":\"mixed_db_files_fixture_coherent\",\"text\":\"mixed database/file workflows keep database `list` limits, database `maxRecords`, and file `maxFiles` distinct and dimensionally coherent\"},{\"id\":\"exact_file_transport\",\"text\":\"file inputs are browser `File` values and downloads use `contentBase64`\"},{\"id\":\"no_invented_storage_authority\",\"text\":\"no public/presigned/storage URLs, filesystem paths, internal metadata, or unsupported sharing are invented\"},{\"id\":\"server_entitlement_authority\",\"text\":\"server entitlement is never inferred from the package\"},{\"id\":\"visible_errors\",\"text\":\"errors are visible and do not falsely report successful storage\"}]}}",
      "metadata": {
        "runtimeStatus": "runtime_available",
        "builderSelectable": true,
        "instructionVisible": true,
        "entitlementAuthority": "aqteron_validator_runtime",
        "presentation": {
          "locales": {
            "en": {
              "name": "App Files",
              "summary": "Guarded private file storage for entitled applications when canonical readiness controls pass."
            },
            "fr": {
              "name": "Fichiers de l'application",
              "summary": "Stockage de fichiers privés protégé pour les applications autorisées lorsque les contrôles de disponibilité canoniques réussissent."
            },
            "ru": {
              "name": "Файлы приложения",
              "summary": "Защищённое приватное хранилище файлов для приложений с правом доступа при успешной канонической проверке готовности."
            }
          }
        },
        "sourcePath": "capabilities/APP_FILES.md",
        "selectionMetadata": {
          "schemaVersion": "aqteron.builder.selection_metadata.v1",
          "summary": "Guarded private file storage for entitled applications when canonical readiness controls pass.",
          "userNeeds": [
            "store user files, attachments, images, documents, imports, or exports",
            "keep private application-scoped files in managed storage",
            "associate files with app workflows"
          ],
          "selectionSignals": [
            "managed private files are required and server-side entitlement is available",
            "files must persist outside local browser storage",
            "workflow references uploaded or generated files"
          ],
          "exclusions": [
            "workflows that can remain entirely in local browser storage",
            "public hosting or public URL generation",
            "shared-drive behavior across unrelated apps or users",
            "structured JSON record storage without files"
          ],
          "dependencies": [],
          "compatibility": {
            "contracts": [
              "Aqteron PWA v1"
            ],
            "requires": [],
            "conflicts": []
          },
          "runtime": {
            "adapterId": "app_files@1"
          },
          "availability": {
            "instructionStatus": "activation_candidate",
            "registryStatus": "available",
            "runtimeStatus": "runtime_available",
            "builderSelectable": true,
            "instructionVisible": true,
            "entitlementAuthority": "aqteron_validator_runtime",
            "notSelectableReason": null
          }
        },
        "selfCheckMetadata": {
          "schemaVersion": "aqteron.builder.module_self_check.v1",
          "instructionModuleId": "aqteron.capability.app_files@1",
          "moduleKind": "capability",
          "required": true,
          "appliesWhenSelected": true,
          "sourceHeading": "Module self-check",
          "checks": [
            {
              "id": "declared_when_helper_used",
              "text": "capability is declared if `appFiles` is used"
            },
            {
              "id": "only_prompt2app_helper",
              "text": "only the exact `window.Prompt2App.appFiles` methods above are used"
            },
            {
              "id": "subject_mode_identity_matches",
              "text": "identity handling matches the declared subject mode: `app_user` requires trusted app-local sign-in, `app` does not account-link, and only legacy no-`subjectMode` declarations may call `connectAccount()`"
            },
            {
              "id": "no_client_file_identity_authority",
              "text": "no client-provided user/subject identifier is used as file authorization authority"
            },
            {
              "id": "used_buckets_declared_private",
              "text": "every used bucket is declared and private"
            },
            {
              "id": "file_quota_dimensions_coherent",
              "text": "MIME types are bounded and `maxFileSizeBytes`, `maxTotalBytes`, and `maxFiles` are validated as separate dimensions within their exact ceilings"
            },
            {
              "id": "mixed_db_files_fixture_coherent",
              "text": "mixed database/file workflows keep database `list` limits, database `maxRecords`, and file `maxFiles` distinct and dimensionally coherent"
            },
            {
              "id": "exact_file_transport",
              "text": "file inputs are browser `File` values and downloads use `contentBase64`"
            },
            {
              "id": "no_invented_storage_authority",
              "text": "no public/presigned/storage URLs, filesystem paths, internal metadata, or unsupported sharing are invented"
            },
            {
              "id": "server_entitlement_authority",
              "text": "server entitlement is never inferred from the package"
            },
            {
              "id": "visible_errors",
              "text": "errors are visible and do not falsely report successful storage"
            }
          ]
        }
      },
      "createdAt": "2026-09-16T05:00:00.000Z",
      "updatedAt": "2026-09-21T05:10:00.000Z"
    },
    {
      "capabilityKey": "app_jobs@1",
      "instructionModuleId": "aqteron.capability.app_jobs@1",
      "instructionModuleVersionId": "aqteron.capability.app_jobs@1@0.1.0",
      "registryStatus": "available",
      "displayName": "App Jobs",
      "summary": "Bounded delayed and retryable external API actions executed by a managed worker.",
      "metadataJson": "{\"runtimeStatus\":\"runtime_available\",\"builderSelectable\":true,\"instructionVisible\":true,\"entitlementAuthority\":\"aqteron_validator_runtime\",\"presentation\":{\"locales\":{\"en\":{\"name\":\"App Jobs\",\"summary\":\"Bounded delayed and retryable external API actions executed by a managed worker.\"},\"fr\":{\"name\":\"Tâches de l'application\",\"summary\":\"Actions d’API externe différées et réessayables, limitées et exécutées par un worker géré.\"},\"ru\":{\"name\":\"Задачи приложения\",\"summary\":\"Ограниченные отложенные и повторяемые вызовы внешнего API через управляемый воркер.\"}}},\"sourcePath\":\"capabilities/APP_JOBS.md\",\"selectionMetadata\":{\"schemaVersion\":\"aqteron.builder.selection_metadata.v1\",\"summary\":\"Bounded delayed and retryable external API actions executed by a managed worker.\",\"userNeeds\":[\"run an approved external API action later\",\"retry transient external API failures with bounded backoff\",\"inspect and cancel pending managed jobs\"],\"selectionSignals\":[\"the scheduled work is representable as an external_api_proxy request descriptor\",\"one-time delayed execution and bounded retries are sufficient\"],\"exclusions\":[\"arbitrary code execution, cron scripts, unbounded recurring tasks, raw secrets in payloads, or custom background servers\"],\"dependencies\":[\"external_api_proxy@1\",\"app_secrets@1\"],\"compatibility\":{\"contracts\":[\"Aqteron PWA v1\"],\"requires\":[\"external_api_proxy@1\",\"app_secrets@1\"],\"conflicts\":[]},\"runtime\":{\"adapterId\":\"app_jobs@1\"},\"availability\":{\"instructionStatus\":\"draft\",\"registryStatus\":\"available\",\"runtimeStatus\":\"runtime_available\",\"builderSelectable\":true,\"instructionVisible\":true,\"entitlementAuthority\":\"aqteron_validator_runtime\",\"notSelectableReason\":null}},\"selfCheckMetadata\":{\"schemaVersion\":\"aqteron.builder.module_self_check.v1\",\"instructionModuleId\":\"aqteron.capability.app_jobs@1\",\"moduleKind\":\"capability\",\"required\":true,\"appliesWhenSelected\":true,\"sourceHeading\":\"Module self-check\",\"checks\":[{\"id\":\"dependencies_declared\",\"text\":\"`external_api_proxy@1` and required `app_secrets@1` references are declared\"},{\"id\":\"request_allowlisted\",\"text\":\"every scheduled request satisfies the declared external API domain and method allowlist\"},{\"id\":\"bounded_schedule\",\"text\":\"run time, queue size, retry count, and retry delay stay inside declared bounds\"},{\"id\":\"idempotency_key\",\"text\":\"each logical scheduled action uses a stable non-secret idempotency key\"},{\"id\":\"no_raw_credentials\",\"text\":\"scheduled job payloads contain no raw credentials or arbitrary backend code\"},{\"id\":\"app_user_dependency\",\"text\":\"`authMode: \\\"app_user\\\"` also declares enabled `app_users@1`\"},{\"id\":\"managed_helper_only\",\"text\":\"generated code uses only the managed job status/schedule/list/get/cancel helpers\"}]}}",
      "metadata": {
        "runtimeStatus": "runtime_available",
        "builderSelectable": true,
        "instructionVisible": true,
        "entitlementAuthority": "aqteron_validator_runtime",
        "presentation": {
          "locales": {
            "en": {
              "name": "App Jobs",
              "summary": "Bounded delayed and retryable external API actions executed by a managed worker."
            },
            "fr": {
              "name": "Tâches de l'application",
              "summary": "Actions d’API externe différées et réessayables, limitées et exécutées par un worker géré."
            },
            "ru": {
              "name": "Задачи приложения",
              "summary": "Ограниченные отложенные и повторяемые вызовы внешнего API через управляемый воркер."
            }
          }
        },
        "sourcePath": "capabilities/APP_JOBS.md",
        "selectionMetadata": {
          "schemaVersion": "aqteron.builder.selection_metadata.v1",
          "summary": "Bounded delayed and retryable external API actions executed by a managed worker.",
          "userNeeds": [
            "run an approved external API action later",
            "retry transient external API failures with bounded backoff",
            "inspect and cancel pending managed jobs"
          ],
          "selectionSignals": [
            "the scheduled work is representable as an external_api_proxy request descriptor",
            "one-time delayed execution and bounded retries are sufficient"
          ],
          "exclusions": [
            "arbitrary code execution, cron scripts, unbounded recurring tasks, raw secrets in payloads, or custom background servers"
          ],
          "dependencies": [
            "external_api_proxy@1",
            "app_secrets@1"
          ],
          "compatibility": {
            "contracts": [
              "Aqteron PWA v1"
            ],
            "requires": [
              "external_api_proxy@1",
              "app_secrets@1"
            ],
            "conflicts": []
          },
          "runtime": {
            "adapterId": "app_jobs@1"
          },
          "availability": {
            "instructionStatus": "draft",
            "registryStatus": "available",
            "runtimeStatus": "runtime_available",
            "builderSelectable": true,
            "instructionVisible": true,
            "entitlementAuthority": "aqteron_validator_runtime",
            "notSelectableReason": null
          }
        },
        "selfCheckMetadata": {
          "schemaVersion": "aqteron.builder.module_self_check.v1",
          "instructionModuleId": "aqteron.capability.app_jobs@1",
          "moduleKind": "capability",
          "required": true,
          "appliesWhenSelected": true,
          "sourceHeading": "Module self-check",
          "checks": [
            {
              "id": "dependencies_declared",
              "text": "`external_api_proxy@1` and required `app_secrets@1` references are declared"
            },
            {
              "id": "request_allowlisted",
              "text": "every scheduled request satisfies the declared external API domain and method allowlist"
            },
            {
              "id": "bounded_schedule",
              "text": "run time, queue size, retry count, and retry delay stay inside declared bounds"
            },
            {
              "id": "idempotency_key",
              "text": "each logical scheduled action uses a stable non-secret idempotency key"
            },
            {
              "id": "no_raw_credentials",
              "text": "scheduled job payloads contain no raw credentials or arbitrary backend code"
            },
            {
              "id": "app_user_dependency",
              "text": "`authMode: \"app_user\"` also declares enabled `app_users@1`"
            },
            {
              "id": "managed_helper_only",
              "text": "generated code uses only the managed job status/schedule/list/get/cancel helpers"
            }
          ]
        }
      },
      "createdAt": "2026-09-21T10:50:00.000Z",
      "updatedAt": "2026-09-21T10:50:00.000Z"
    },
    {
      "capabilityKey": "app_secrets@1",
      "instructionModuleId": "aqteron.capability.app_secrets@1",
      "instructionModuleVersionId": "aqteron.capability.app_secrets@1@0.1.0",
      "registryStatus": "available",
      "displayName": "App Secrets",
      "summary": "Server-held encrypted credential references that are never exposed to generated app JavaScript.",
      "metadataJson": "{\"runtimeStatus\":\"runtime_available\",\"builderSelectable\":true,\"instructionVisible\":true,\"entitlementAuthority\":\"aqteron_validator_runtime\",\"presentation\":{\"locales\":{\"en\":{\"name\":\"App Secrets\",\"summary\":\"Server-held encrypted credential references that are never exposed to generated app JavaScript.\"},\"fr\":{\"name\":\"Secrets de l'application\",\"summary\":\"Références d’identifiants chiffrées conservées côté serveur et jamais exposées au JavaScript de l’application.\"},\"ru\":{\"name\":\"Секреты приложения\",\"summary\":\"Зашифрованные серверные ссылки на учётные данные без передачи исходных значений JavaScript приложения.\"}}},\"sourcePath\":\"capabilities/APP_SECRETS.md\",\"selectionMetadata\":{\"schemaVersion\":\"aqteron.builder.selection_metadata.v1\",\"summary\":\"Server-held encrypted credential references that are never exposed to generated app JavaScript.\",\"userNeeds\":[\"store third-party API credentials without exposing them to browser code\",\"let the app owner configure named server-held credential references\",\"rotate or revoke integration credentials without rebuilding the application\"],\"selectionSignals\":[\"an external integration needs an API key, token, or signing secret\",\"the credential must remain server-side\",\"the user can configure the credential after publication\"],\"exclusions\":[\"embedding raw credentials in ZIP files, metadata, JavaScript, browser storage, logs, or job payloads\",\"using app_secrets as general user data storage\"],\"dependencies\":[],\"compatibility\":{\"contracts\":[\"Aqteron PWA v1\"],\"requires\":[],\"conflicts\":[]},\"runtime\":{\"adapterId\":\"app_secrets@1\"},\"availability\":{\"instructionStatus\":\"draft\",\"registryStatus\":\"available\",\"runtimeStatus\":\"runtime_available\",\"builderSelectable\":true,\"instructionVisible\":true,\"entitlementAuthority\":\"aqteron_validator_runtime\",\"notSelectableReason\":null}},\"selfCheckMetadata\":{\"schemaVersion\":\"aqteron.builder.module_self_check.v1\",\"instructionModuleId\":\"aqteron.capability.app_secrets@1\",\"moduleKind\":\"capability\",\"required\":true,\"appliesWhenSelected\":true,\"sourceHeading\":\"Module self-check\",\"checks\":[{\"id\":\"declared_when_needed\",\"text\":\"`app_secrets@1` is declared whenever server-held integration credentials are required\"},{\"id\":\"refs_declared\",\"text\":\"every credential reference used by another capability is declared in `config.refs`\"},{\"id\":\"no_raw_secret_in_package\",\"text\":\"no raw secret value appears in ZIP files, metadata, JavaScript, browser storage, logs, webhook payloads, or job payloads\"},{\"id\":\"status_only_browser\",\"text\":\"generated app code uses only status visibility and never expects a raw secret value\"},{\"id\":\"owner_configuration\",\"text\":\"the user-facing flow explains that the application owner configures the credential in Aqteron\"},{\"id\":\"rotation_safe\",\"text\":\"rotation or revocation does not require rebuilding the generated application\"}]}}",
      "metadata": {
        "runtimeStatus": "runtime_available",
        "builderSelectable": true,
        "instructionVisible": true,
        "entitlementAuthority": "aqteron_validator_runtime",
        "presentation": {
          "locales": {
            "en": {
              "name": "App Secrets",
              "summary": "Server-held encrypted credential references that are never exposed to generated app JavaScript."
            },
            "fr": {
              "name": "Secrets de l'application",
              "summary": "Références d’identifiants chiffrées conservées côté serveur et jamais exposées au JavaScript de l’application."
            },
            "ru": {
              "name": "Секреты приложения",
              "summary": "Зашифрованные серверные ссылки на учётные данные без передачи исходных значений JavaScript приложения."
            }
          }
        },
        "sourcePath": "capabilities/APP_SECRETS.md",
        "selectionMetadata": {
          "schemaVersion": "aqteron.builder.selection_metadata.v1",
          "summary": "Server-held encrypted credential references that are never exposed to generated app JavaScript.",
          "userNeeds": [
            "store third-party API credentials without exposing them to browser code",
            "let the app owner configure named server-held credential references",
            "rotate or revoke integration credentials without rebuilding the application"
          ],
          "selectionSignals": [
            "an external integration needs an API key, token, or signing secret",
            "the credential must remain server-side",
            "the user can configure the credential after publication"
          ],
          "exclusions": [
            "embedding raw credentials in ZIP files, metadata, JavaScript, browser storage, logs, or job payloads",
            "using app_secrets as general user data storage"
          ],
          "dependencies": [],
          "compatibility": {
            "contracts": [
              "Aqteron PWA v1"
            ],
            "requires": [],
            "conflicts": []
          },
          "runtime": {
            "adapterId": "app_secrets@1"
          },
          "availability": {
            "instructionStatus": "draft",
            "registryStatus": "available",
            "runtimeStatus": "runtime_available",
            "builderSelectable": true,
            "instructionVisible": true,
            "entitlementAuthority": "aqteron_validator_runtime",
            "notSelectableReason": null
          }
        },
        "selfCheckMetadata": {
          "schemaVersion": "aqteron.builder.module_self_check.v1",
          "instructionModuleId": "aqteron.capability.app_secrets@1",
          "moduleKind": "capability",
          "required": true,
          "appliesWhenSelected": true,
          "sourceHeading": "Module self-check",
          "checks": [
            {
              "id": "declared_when_needed",
              "text": "`app_secrets@1` is declared whenever server-held integration credentials are required"
            },
            {
              "id": "refs_declared",
              "text": "every credential reference used by another capability is declared in `config.refs`"
            },
            {
              "id": "no_raw_secret_in_package",
              "text": "no raw secret value appears in ZIP files, metadata, JavaScript, browser storage, logs, webhook payloads, or job payloads"
            },
            {
              "id": "status_only_browser",
              "text": "generated app code uses only status visibility and never expects a raw secret value"
            },
            {
              "id": "owner_configuration",
              "text": "the user-facing flow explains that the application owner configures the credential in Aqteron"
            },
            {
              "id": "rotation_safe",
              "text": "rotation or revocation does not require rebuilding the generated application"
            }
          ]
        }
      },
      "createdAt": "2026-09-21T10:50:00.000Z",
      "updatedAt": "2026-09-21T10:50:00.000Z"
    },
    {
      "capabilityKey": "app_users@1",
      "instructionModuleId": "aqteron.capability.app_users@1",
      "instructionModuleVersionId": "aqteron.capability.app_users@1@0.1.1",
      "registryStatus": "available",
      "displayName": "App Users",
      "summary": "Isolated application-local user accounts, sessions, roles, permissions, and credential recovery.",
      "metadataJson": "{\"runtimeStatus\":\"runtime_available\",\"builderSelectable\":true,\"instructionVisible\":true,\"entitlementAuthority\":\"aqteron_validator_runtime\",\"presentation\":{\"locales\":{\"en\":{\"name\":\"App Users\",\"summary\":\"Isolated application-local user accounts, sessions, roles, permissions, and credential recovery.\"},\"fr\":{\"name\":\"Utilisateurs de l'application\",\"summary\":\"Comptes, sessions, rôles, autorisations et récupération d’identifiants isolés pour chaque application.\"},\"ru\":{\"name\":\"Пользователи приложения\",\"summary\":\"Изолированные локальные аккаунты приложения, сессии, роли, права и восстановление учётных данных.\"}}},\"sourcePath\":\"capabilities/APP_USERS.md\",\"selectionMetadata\":{\"schemaVersion\":\"aqteron.builder.selection_metadata.v1\",\"summary\":\"Isolated application-local user accounts, sessions, roles, permissions, and credential recovery.\",\"userNeeds\":[\"let visitors create or use accounts that belong only to the application\",\"maintain application-local sign-in sessions across visits\",\"check application-local roles or permissions\"],\"selectionSignals\":[\"the requested workflow needs sign-in that must not depend on Aqteron platform accounts\",\"multiple end users need distinct identities inside one published application\",\"managed credential hashing, lockout, recovery, or session revocation is required\"],\"exclusions\":[\"Aqteron platform account authentication or account linking\",\"custom authentication servers or direct credential storage\",\"workflows that need no user identity\"],\"dependencies\":[],\"compatibility\":{\"contracts\":[\"Aqteron PWA v1\"],\"requires\":[],\"conflicts\":[]},\"runtime\":{\"adapterId\":\"app_users@1\"},\"availability\":{\"instructionStatus\":\"draft\",\"registryStatus\":\"available\",\"runtimeStatus\":\"runtime_available\",\"builderSelectable\":true,\"instructionVisible\":true,\"entitlementAuthority\":\"aqteron_validator_runtime\",\"notSelectableReason\":null}},\"selfCheckMetadata\":{\"schemaVersion\":\"aqteron.builder.module_self_check.v1\",\"instructionModuleId\":\"aqteron.capability.app_users@1\",\"moduleKind\":\"capability\",\"required\":true,\"appliesWhenSelected\":true,\"sourceHeading\":\"Module self-check\",\"checks\":[{\"id\":\"declared_when_helper_used\",\"text\":\"`app_users@1` is declared whenever `appUsers` is used\"},{\"id\":\"supported_methods_only\",\"text\":\"only the exact `window.Prompt2App.appUsers` public methods above are used\"},{\"id\":\"platform_identity_separate\",\"text\":\"app users are never treated as Aqteron platform accounts\"},{\"id\":\"no_custom_auth_backend\",\"text\":\"no custom authentication backend or private app-user route is invented\"},{\"id\":\"no_raw_auth_secrets\",\"text\":\"raw passwords, PINs, recovery codes, session tokens, and cookies are never persisted by generated code\"},{\"id\":\"registration_mode_matches\",\"text\":\"registration UI matches the declared `registrationMode`\"},{\"id\":\"bounded_security_policy\",\"text\":\"credential types and session/lockout bounds match the declaration contract\"},{\"id\":\"permission_boundary\",\"text\":\"permission checks do not rely on hiding UI as server authorization\"},{\"id\":\"admin_ops_not_public\",\"text\":\"role assignment and recovery-code issuance are not exposed as public browser operations\"},{\"id\":\"trusted_cross_capability_authority\",\"text\":\"capability combinations that require app-user authority derive it only from the trusted server session and never from client-selected user IDs\"},{\"id\":\"current_binding_modes\",\"text\":\"per-user files use `subjectMode: \\\"app_user\\\"`, database sign-in gates use `authMode: \\\"app_user\\\"`, and push does not account-link when `app_users@1` is enabled\"},{\"id\":\"visible_auth_states\",\"text\":\"authentication, lockout, recovery, and unavailable states are shown clearly to the user\"}]}}",
      "metadata": {
        "runtimeStatus": "runtime_available",
        "builderSelectable": true,
        "instructionVisible": true,
        "entitlementAuthority": "aqteron_validator_runtime",
        "presentation": {
          "locales": {
            "en": {
              "name": "App Users",
              "summary": "Isolated application-local user accounts, sessions, roles, permissions, and credential recovery."
            },
            "fr": {
              "name": "Utilisateurs de l'application",
              "summary": "Comptes, sessions, rôles, autorisations et récupération d’identifiants isolés pour chaque application."
            },
            "ru": {
              "name": "Пользователи приложения",
              "summary": "Изолированные локальные аккаунты приложения, сессии, роли, права и восстановление учётных данных."
            }
          }
        },
        "sourcePath": "capabilities/APP_USERS.md",
        "selectionMetadata": {
          "schemaVersion": "aqteron.builder.selection_metadata.v1",
          "summary": "Isolated application-local user accounts, sessions, roles, permissions, and credential recovery.",
          "userNeeds": [
            "let visitors create or use accounts that belong only to the application",
            "maintain application-local sign-in sessions across visits",
            "check application-local roles or permissions"
          ],
          "selectionSignals": [
            "the requested workflow needs sign-in that must not depend on Aqteron platform accounts",
            "multiple end users need distinct identities inside one published application",
            "managed credential hashing, lockout, recovery, or session revocation is required"
          ],
          "exclusions": [
            "Aqteron platform account authentication or account linking",
            "custom authentication servers or direct credential storage",
            "workflows that need no user identity"
          ],
          "dependencies": [],
          "compatibility": {
            "contracts": [
              "Aqteron PWA v1"
            ],
            "requires": [],
            "conflicts": []
          },
          "runtime": {
            "adapterId": "app_users@1"
          },
          "availability": {
            "instructionStatus": "draft",
            "registryStatus": "available",
            "runtimeStatus": "runtime_available",
            "builderSelectable": true,
            "instructionVisible": true,
            "entitlementAuthority": "aqteron_validator_runtime",
            "notSelectableReason": null
          }
        },
        "selfCheckMetadata": {
          "schemaVersion": "aqteron.builder.module_self_check.v1",
          "instructionModuleId": "aqteron.capability.app_users@1",
          "moduleKind": "capability",
          "required": true,
          "appliesWhenSelected": true,
          "sourceHeading": "Module self-check",
          "checks": [
            {
              "id": "declared_when_helper_used",
              "text": "`app_users@1` is declared whenever `appUsers` is used"
            },
            {
              "id": "supported_methods_only",
              "text": "only the exact `window.Prompt2App.appUsers` public methods above are used"
            },
            {
              "id": "platform_identity_separate",
              "text": "app users are never treated as Aqteron platform accounts"
            },
            {
              "id": "no_custom_auth_backend",
              "text": "no custom authentication backend or private app-user route is invented"
            },
            {
              "id": "no_raw_auth_secrets",
              "text": "raw passwords, PINs, recovery codes, session tokens, and cookies are never persisted by generated code"
            },
            {
              "id": "registration_mode_matches",
              "text": "registration UI matches the declared `registrationMode`"
            },
            {
              "id": "bounded_security_policy",
              "text": "credential types and session/lockout bounds match the declaration contract"
            },
            {
              "id": "permission_boundary",
              "text": "permission checks do not rely on hiding UI as server authorization"
            },
            {
              "id": "admin_ops_not_public",
              "text": "role assignment and recovery-code issuance are not exposed as public browser operations"
            },
            {
              "id": "trusted_cross_capability_authority",
              "text": "capability combinations that require app-user authority derive it only from the trusted server session and never from client-selected user IDs"
            },
            {
              "id": "current_binding_modes",
              "text": "per-user files use `subjectMode: \"app_user\"`, database sign-in gates use `authMode: \"app_user\"`, and push does not account-link when `app_users@1` is enabled"
            },
            {
              "id": "visible_auth_states",
              "text": "authentication, lockout, recovery, and unavailable states are shown clearly to the user"
            }
          ]
        }
      },
      "createdAt": "2026-09-16T05:00:00.000Z",
      "updatedAt": "2026-09-21T05:10:00.000Z"
    },
    {
      "capabilityKey": "app_webhooks@1",
      "instructionModuleId": "aqteron.capability.app_webhooks@1",
      "instructionModuleVersionId": "aqteron.capability.app_webhooks@1@0.1.0",
      "registryStatus": "available",
      "displayName": "App Webhooks",
      "summary": "Verified bounded inbound JSON webhook events isolated per Application Environment.",
      "metadataJson": "{\"runtimeStatus\":\"runtime_available\",\"builderSelectable\":true,\"instructionVisible\":true,\"entitlementAuthority\":\"aqteron_validator_runtime\",\"presentation\":{\"locales\":{\"en\":{\"name\":\"App Webhooks\",\"summary\":\"Verified bounded inbound JSON webhook events isolated per Application Environment.\"},\"fr\":{\"name\":\"Webhooks de l'application\",\"summary\":\"Événements webhook JSON entrants, vérifiés et limités, isolés par environnement d’application.\"},\"ru\":{\"name\":\"Вебхуки приложения\",\"summary\":\"Проверенные ограниченные входящие JSON-вебхуки, изолированные в среде приложения.\"}}},\"sourcePath\":\"capabilities/APP_WEBHOOKS.md\",\"selectionMetadata\":{\"schemaVersion\":\"aqteron.builder.selection_metadata.v1\",\"summary\":\"Verified bounded inbound JSON webhook events isolated per Application Environment.\",\"userNeeds\":[\"receive signed events from an external provider\",\"consume bounded verified JSON callbacks\",\"avoid exposing webhook signing material to browser code\"],\"selectionSignals\":[\"the provider can send HMAC-SHA256 signed JSON to a stable app webhook endpoint\",\"bounded retention and polling are sufficient\"],\"exclusions\":[\"unsigned callbacks, arbitrary request bodies, raw credential transport, or custom webhook servers\"],\"dependencies\":[\"app_secrets@1\"],\"compatibility\":{\"contracts\":[\"Aqteron PWA v1\"],\"requires\":[\"app_secrets@1\"],\"conflicts\":[]},\"runtime\":{\"adapterId\":\"app_webhooks@1\"},\"availability\":{\"instructionStatus\":\"draft\",\"registryStatus\":\"available\",\"runtimeStatus\":\"runtime_available\",\"builderSelectable\":true,\"instructionVisible\":true,\"entitlementAuthority\":\"aqteron_validator_runtime\",\"notSelectableReason\":null}},\"selfCheckMetadata\":{\"schemaVersion\":\"aqteron.builder.module_self_check.v1\",\"instructionModuleId\":\"aqteron.capability.app_webhooks@1\",\"moduleKind\":\"capability\",\"required\":true,\"appliesWhenSelected\":true,\"sourceHeading\":\"Module self-check\",\"checks\":[{\"id\":\"declared_hook\",\"text\":\"every webhook consumed by the app has a declared safe hook ID\"},{\"id\":\"signing_ref_declared\",\"text\":\"every hook signing reference exists in `app_secrets@1`\"},{\"id\":\"bounded_inbound\",\"text\":\"body size, retention, and event count are bounded\"},{\"id\":\"verified_events_only\",\"text\":\"browser code consumes only verified events through managed status/poll/ack helpers\"},{\"id\":\"no_signing_secret_exposure\",\"text\":\"signing secrets are never embedded or returned to browser code\"},{\"id\":\"app_user_dependency\",\"text\":\"`authMode: \\\"app_user\\\"` also declares enabled `app_users@1` when used\"}]}}",
      "metadata": {
        "runtimeStatus": "runtime_available",
        "builderSelectable": true,
        "instructionVisible": true,
        "entitlementAuthority": "aqteron_validator_runtime",
        "presentation": {
          "locales": {
            "en": {
              "name": "App Webhooks",
              "summary": "Verified bounded inbound JSON webhook events isolated per Application Environment."
            },
            "fr": {
              "name": "Webhooks de l'application",
              "summary": "Événements webhook JSON entrants, vérifiés et limités, isolés par environnement d’application."
            },
            "ru": {
              "name": "Вебхуки приложения",
              "summary": "Проверенные ограниченные входящие JSON-вебхуки, изолированные в среде приложения."
            }
          }
        },
        "sourcePath": "capabilities/APP_WEBHOOKS.md",
        "selectionMetadata": {
          "schemaVersion": "aqteron.builder.selection_metadata.v1",
          "summary": "Verified bounded inbound JSON webhook events isolated per Application Environment.",
          "userNeeds": [
            "receive signed events from an external provider",
            "consume bounded verified JSON callbacks",
            "avoid exposing webhook signing material to browser code"
          ],
          "selectionSignals": [
            "the provider can send HMAC-SHA256 signed JSON to a stable app webhook endpoint",
            "bounded retention and polling are sufficient"
          ],
          "exclusions": [
            "unsigned callbacks, arbitrary request bodies, raw credential transport, or custom webhook servers"
          ],
          "dependencies": [
            "app_secrets@1"
          ],
          "compatibility": {
            "contracts": [
              "Aqteron PWA v1"
            ],
            "requires": [
              "app_secrets@1"
            ],
            "conflicts": []
          },
          "runtime": {
            "adapterId": "app_webhooks@1"
          },
          "availability": {
            "instructionStatus": "draft",
            "registryStatus": "available",
            "runtimeStatus": "runtime_available",
            "builderSelectable": true,
            "instructionVisible": true,
            "entitlementAuthority": "aqteron_validator_runtime",
            "notSelectableReason": null
          }
        },
        "selfCheckMetadata": {
          "schemaVersion": "aqteron.builder.module_self_check.v1",
          "instructionModuleId": "aqteron.capability.app_webhooks@1",
          "moduleKind": "capability",
          "required": true,
          "appliesWhenSelected": true,
          "sourceHeading": "Module self-check",
          "checks": [
            {
              "id": "declared_hook",
              "text": "every webhook consumed by the app has a declared safe hook ID"
            },
            {
              "id": "signing_ref_declared",
              "text": "every hook signing reference exists in `app_secrets@1`"
            },
            {
              "id": "bounded_inbound",
              "text": "body size, retention, and event count are bounded"
            },
            {
              "id": "verified_events_only",
              "text": "browser code consumes only verified events through managed status/poll/ack helpers"
            },
            {
              "id": "no_signing_secret_exposure",
              "text": "signing secrets are never embedded or returned to browser code"
            },
            {
              "id": "app_user_dependency",
              "text": "`authMode: \"app_user\"` also declares enabled `app_users@1` when used"
            }
          ]
        }
      },
      "createdAt": "2026-09-21T10:50:00.000Z",
      "updatedAt": "2026-09-21T10:50:00.000Z"
    },
    {
      "capabilityKey": "external_api_proxy@1",
      "instructionModuleId": "aqteron.capability.external_api_proxy@1",
      "instructionModuleVersionId": "aqteron.capability.external_api_proxy@1@0.1.0",
      "registryStatus": "available",
      "displayName": "External API Proxy",
      "summary": "Allowlisted bounded HTTPS calls with server-held authentication and SSRF protection.",
      "metadataJson": "{\"runtimeStatus\":\"runtime_available\",\"builderSelectable\":true,\"instructionVisible\":true,\"entitlementAuthority\":\"aqteron_validator_runtime\",\"presentation\":{\"locales\":{\"en\":{\"name\":\"External API Proxy\",\"summary\":\"Allowlisted bounded HTTPS calls with server-held authentication and SSRF protection.\"},\"fr\":{\"name\":\"Proxy d'API externe\",\"summary\":\"Appels HTTPS limités vers des domaines autorisés, avec authentification côté serveur et protection SSRF.\"},\"ru\":{\"name\":\"Прокси внешнего API\",\"summary\":\"Ограниченные HTTPS-вызовы к разрешённым доменам с серверной аутентификацией и защитой от SSRF.\"}}},\"sourcePath\":\"capabilities/EXTERNAL_API_PROXY.md\",\"selectionMetadata\":{\"schemaVersion\":\"aqteron.builder.selection_metadata.v1\",\"summary\":\"Allowlisted bounded HTTPS calls with server-held authentication and SSRF protection.\",\"userNeeds\":[\"call a specific approved external HTTPS API\",\"use server-held authentication for a third-party provider\",\"keep outbound network access bounded and auditable\"],\"selectionSignals\":[\"the workflow explicitly depends on one or more known public API domains\",\"declared methods, body sizes, timeouts, and quotas are sufficient\",\"the provider can be called without arbitrary headers or redirects\"],\"exclusions\":[\"arbitrary internet access, crawling, private/internal URLs, custom ports, raw sockets, or browser automation\",\"client-supplied Authorization/Cookie headers or absolute URLs\"],\"dependencies\":[\"app_secrets@1\"],\"compatibility\":{\"contracts\":[\"Aqteron PWA v1\"],\"requires\":[\"app_secrets@1\"],\"conflicts\":[]},\"runtime\":{\"adapterId\":\"external_api_proxy@1\"},\"availability\":{\"instructionStatus\":\"draft\",\"registryStatus\":\"available\",\"runtimeStatus\":\"runtime_available\",\"builderSelectable\":true,\"instructionVisible\":true,\"entitlementAuthority\":\"aqteron_validator_runtime\",\"notSelectableReason\":null}},\"selfCheckMetadata\":{\"schemaVersion\":\"aqteron.builder.module_self_check.v1\",\"instructionModuleId\":\"aqteron.capability.external_api_proxy@1\",\"moduleKind\":\"capability\",\"required\":true,\"appliesWhenSelected\":true,\"sourceHeading\":\"Module self-check\",\"checks\":[{\"id\":\"declared_domain_method\",\"text\":\"every external API domain and HTTP method used by the app is explicitly declared\"},{\"id\":\"server_held_auth\",\"text\":\"authentication uses only declared `app_secrets@1` references\"},{\"id\":\"relative_request_only\",\"text\":\"generated code sends only domain, method, relative path, bounded query, and optional JSON body\"},{\"id\":\"no_client_headers_or_url\",\"text\":\"no absolute URL, arbitrary headers, Authorization/Cookie value, protocol, port, host override, or IP target is client supplied\"},{\"id\":\"bounded_network_limits\",\"text\":\"timeout, request bytes, response bytes, and requests-per-minute quota are declared and bounded\"},{\"id\":\"app_user_dependency\",\"text\":\"`authMode: \\\"app_user\\\"` also declares enabled `app_users@1`\"},{\"id\":\"managed_helper_only\",\"text\":\"generated code uses only the managed external API helper\"}]}}",
      "metadata": {
        "runtimeStatus": "runtime_available",
        "builderSelectable": true,
        "instructionVisible": true,
        "entitlementAuthority": "aqteron_validator_runtime",
        "presentation": {
          "locales": {
            "en": {
              "name": "External API Proxy",
              "summary": "Allowlisted bounded HTTPS calls with server-held authentication and SSRF protection."
            },
            "fr": {
              "name": "Proxy d'API externe",
              "summary": "Appels HTTPS limités vers des domaines autorisés, avec authentification côté serveur et protection SSRF."
            },
            "ru": {
              "name": "Прокси внешнего API",
              "summary": "Ограниченные HTTPS-вызовы к разрешённым доменам с серверной аутентификацией и защитой от SSRF."
            }
          }
        },
        "sourcePath": "capabilities/EXTERNAL_API_PROXY.md",
        "selectionMetadata": {
          "schemaVersion": "aqteron.builder.selection_metadata.v1",
          "summary": "Allowlisted bounded HTTPS calls with server-held authentication and SSRF protection.",
          "userNeeds": [
            "call a specific approved external HTTPS API",
            "use server-held authentication for a third-party provider",
            "keep outbound network access bounded and auditable"
          ],
          "selectionSignals": [
            "the workflow explicitly depends on one or more known public API domains",
            "declared methods, body sizes, timeouts, and quotas are sufficient",
            "the provider can be called without arbitrary headers or redirects"
          ],
          "exclusions": [
            "arbitrary internet access, crawling, private/internal URLs, custom ports, raw sockets, or browser automation",
            "client-supplied Authorization/Cookie headers or absolute URLs"
          ],
          "dependencies": [
            "app_secrets@1"
          ],
          "compatibility": {
            "contracts": [
              "Aqteron PWA v1"
            ],
            "requires": [
              "app_secrets@1"
            ],
            "conflicts": []
          },
          "runtime": {
            "adapterId": "external_api_proxy@1"
          },
          "availability": {
            "instructionStatus": "draft",
            "registryStatus": "available",
            "runtimeStatus": "runtime_available",
            "builderSelectable": true,
            "instructionVisible": true,
            "entitlementAuthority": "aqteron_validator_runtime",
            "notSelectableReason": null
          }
        },
        "selfCheckMetadata": {
          "schemaVersion": "aqteron.builder.module_self_check.v1",
          "instructionModuleId": "aqteron.capability.external_api_proxy@1",
          "moduleKind": "capability",
          "required": true,
          "appliesWhenSelected": true,
          "sourceHeading": "Module self-check",
          "checks": [
            {
              "id": "declared_domain_method",
              "text": "every external API domain and HTTP method used by the app is explicitly declared"
            },
            {
              "id": "server_held_auth",
              "text": "authentication uses only declared `app_secrets@1` references"
            },
            {
              "id": "relative_request_only",
              "text": "generated code sends only domain, method, relative path, bounded query, and optional JSON body"
            },
            {
              "id": "no_client_headers_or_url",
              "text": "no absolute URL, arbitrary headers, Authorization/Cookie value, protocol, port, host override, or IP target is client supplied"
            },
            {
              "id": "bounded_network_limits",
              "text": "timeout, request bytes, response bytes, and requests-per-minute quota are declared and bounded"
            },
            {
              "id": "app_user_dependency",
              "text": "`authMode: \"app_user\"` also declares enabled `app_users@1`"
            },
            {
              "id": "managed_helper_only",
              "text": "generated code uses only the managed external API helper"
            }
          ]
        }
      },
      "createdAt": "2026-09-21T10:50:00.000Z",
      "updatedAt": "2026-09-21T10:50:00.000Z"
    },
    {
      "capabilityKey": "push_notifications@1",
      "instructionModuleId": "aqteron.capability.push_notifications@1",
      "instructionModuleVersionId": "aqteron.capability.push_notifications@1@0.1.5",
      "registryStatus": "available",
      "displayName": "Push Notifications",
      "summary": "Platform-managed push notification subscription and declared trigger support.",
      "metadataJson": "{\"runtimeStatus\":\"runtime_available\",\"builderSelectable\":true,\"instructionVisible\":true,\"entitlementAuthority\":\"aqteron_validator_runtime\",\"presentation\":{\"locales\":{\"en\":{\"name\":\"Push Notifications\",\"summary\":\"Platform-managed push notification subscription and declared trigger support.\"},\"fr\":{\"name\":\"Notifications push\",\"summary\":\"Abonnements aux notifications push gérés par la plateforme et prise en charge des déclencheurs déclarés.\"},\"ru\":{\"name\":\"Push-уведомления\",\"summary\":\"Управляемые платформой подписки на push-уведомления и поддержка объявленных триггеров.\"}}},\"sourcePath\":\"capabilities/PUSH_NOTIFICATIONS.md\",\"selectionMetadata\":{\"schemaVersion\":\"aqteron.builder.selection_metadata.v1\",\"summary\":\"Platform-managed push notification subscription and declared trigger support.\",\"userNeeds\":[\"notify users while the installed or browser PWA is closed\",\"support declared message, reminder, or shared-data alerts\",\"let users subscribe, unsubscribe, and manage notification preferences\"],\"selectionSignals\":[\"user explicitly needs push or closed-app alerts\",\"notification trigger fits the supported platform contract\",\"helper-only subscription controls are sufficient\"],\"exclusions\":[\"custom service workers or direct push provider calls\",\"invented send endpoints or arbitrary server triggers\",\"storing browser subscription secrets in app state\"],\"dependencies\":[],\"compatibility\":{\"contracts\":[\"Aqteron PWA v1\"],\"requires\":[],\"conflicts\":[]},\"runtime\":{\"adapterId\":null},\"availability\":{\"instructionStatus\":\"draft\",\"registryStatus\":\"available\",\"runtimeStatus\":\"runtime_available\",\"builderSelectable\":true,\"instructionVisible\":true,\"entitlementAuthority\":\"aqteron_validator_runtime\",\"notSelectableReason\":null}},\"selfCheckMetadata\":{\"schemaVersion\":\"aqteron.builder.module_self_check.v1\",\"instructionModuleId\":\"aqteron.capability.push_notifications@1\",\"moduleKind\":\"capability\",\"required\":true,\"appliesWhenSelected\":true,\"sourceHeading\":\"Module self-check\",\"checks\":[{\"id\":\"declared_when_helper_used\",\"text\":\"`push_notifications@1` is declared when notifications helper is used\"},{\"id\":\"supported_methods_only\",\"text\":\"only supported helper methods are called and no `send()` exists\"},{\"id\":\"no_app_service_worker_or_provider\",\"text\":\"no application service worker or push-provider endpoint is included\"},{\"id\":\"identity_mode_flow\",\"text\":\"identity flow matches the app: with `app_users@1`, push uses the trusted app-user session and never calls `connectAccount()`; without it, legacy account linking and permission remain separate explicit user actions\"},{\"id\":\"no_client_recipient_identity_authority\",\"text\":\"no client-supplied user identity is treated as recipient ownership authority\"},{\"id\":\"declared_database_trigger_fields\",\"text\":\"triggers use declared `app_database.record.create` fields\"},{\"id\":\"push_create_trigger_uses_create_path\",\"text\":\"every `app_database.record.create` trigger record uses the `appDatabase.put` create path, including offline/deferred replay\"},{\"id\":\"bounded_trigger_fields\",\"text\":\"actor/target/click URL fields exist as bounded strings in the database schema\"},{\"id\":\"same_app_click_url\",\"text\":\"click URL is root-relative and same-app\"},{\"id\":\"bounded_non_private_content\",\"text\":\"notification title/body are bounded and do not expose private message contents\"},{\"id\":\"opaque_recipient_ids\",\"text\":\"opaque recipient IDs are not treated as secrets or modified\"}]}}",
      "metadata": {
        "runtimeStatus": "runtime_available",
        "builderSelectable": true,
        "instructionVisible": true,
        "entitlementAuthority": "aqteron_validator_runtime",
        "presentation": {
          "locales": {
            "en": {
              "name": "Push Notifications",
              "summary": "Platform-managed push notification subscription and declared trigger support."
            },
            "fr": {
              "name": "Notifications push",
              "summary": "Abonnements aux notifications push gérés par la plateforme et prise en charge des déclencheurs déclarés."
            },
            "ru": {
              "name": "Push-уведомления",
              "summary": "Управляемые платформой подписки на push-уведомления и поддержка объявленных триггеров."
            }
          }
        },
        "sourcePath": "capabilities/PUSH_NOTIFICATIONS.md",
        "selectionMetadata": {
          "schemaVersion": "aqteron.builder.selection_metadata.v1",
          "summary": "Platform-managed push notification subscription and declared trigger support.",
          "userNeeds": [
            "notify users while the installed or browser PWA is closed",
            "support declared message, reminder, or shared-data alerts",
            "let users subscribe, unsubscribe, and manage notification preferences"
          ],
          "selectionSignals": [
            "user explicitly needs push or closed-app alerts",
            "notification trigger fits the supported platform contract",
            "helper-only subscription controls are sufficient"
          ],
          "exclusions": [
            "custom service workers or direct push provider calls",
            "invented send endpoints or arbitrary server triggers",
            "storing browser subscription secrets in app state"
          ],
          "dependencies": [],
          "compatibility": {
            "contracts": [
              "Aqteron PWA v1"
            ],
            "requires": [],
            "conflicts": []
          },
          "runtime": {
            "adapterId": null
          },
          "availability": {
            "instructionStatus": "draft",
            "registryStatus": "available",
            "runtimeStatus": "runtime_available",
            "builderSelectable": true,
            "instructionVisible": true,
            "entitlementAuthority": "aqteron_validator_runtime",
            "notSelectableReason": null
          }
        },
        "selfCheckMetadata": {
          "schemaVersion": "aqteron.builder.module_self_check.v1",
          "instructionModuleId": "aqteron.capability.push_notifications@1",
          "moduleKind": "capability",
          "required": true,
          "appliesWhenSelected": true,
          "sourceHeading": "Module self-check",
          "checks": [
            {
              "id": "declared_when_helper_used",
              "text": "`push_notifications@1` is declared when notifications helper is used"
            },
            {
              "id": "supported_methods_only",
              "text": "only supported helper methods are called and no `send()` exists"
            },
            {
              "id": "no_app_service_worker_or_provider",
              "text": "no application service worker or push-provider endpoint is included"
            },
            {
              "id": "identity_mode_flow",
              "text": "identity flow matches the app: with `app_users@1`, push uses the trusted app-user session and never calls `connectAccount()`; without it, legacy account linking and permission remain separate explicit user actions"
            },
            {
              "id": "no_client_recipient_identity_authority",
              "text": "no client-supplied user identity is treated as recipient ownership authority"
            },
            {
              "id": "declared_database_trigger_fields",
              "text": "triggers use declared `app_database.record.create` fields"
            },
            {
              "id": "push_create_trigger_uses_create_path",
              "text": "every `app_database.record.create` trigger record uses the `appDatabase.put` create path, including offline/deferred replay"
            },
            {
              "id": "bounded_trigger_fields",
              "text": "actor/target/click URL fields exist as bounded strings in the database schema"
            },
            {
              "id": "same_app_click_url",
              "text": "click URL is root-relative and same-app"
            },
            {
              "id": "bounded_non_private_content",
              "text": "notification title/body are bounded and do not expose private message contents"
            },
            {
              "id": "opaque_recipient_ids",
              "text": "opaque recipient IDs are not treated as secrets or modified"
            }
          ]
        }
      },
      "createdAt": "2026-09-16T05:00:00.000Z",
      "updatedAt": "2026-09-21T05:10:00.000Z"
    },
    {
      "capabilityKey": "realtime_events@1",
      "instructionModuleId": "aqteron.capability.realtime_events@1",
      "instructionModuleVersionId": "aqteron.capability.realtime_events@1@0.1.1",
      "registryStatus": "available",
      "displayName": "Realtime Events",
      "summary": "Bounded app/user-scoped live update signals with reconnect and replay.",
      "metadataJson": "{\"runtimeStatus\":\"runtime_available\",\"builderSelectable\":true,\"instructionVisible\":true,\"entitlementAuthority\":\"aqteron_validator_runtime\",\"presentation\":{\"locales\":{\"en\":{\"name\":\"Realtime Events\",\"summary\":\"Bounded app/user-scoped live update signals with reconnect and replay.\"},\"fr\":{\"name\":\"Événements temps réel\",\"summary\":\"Signaux de mise à jour en temps réel limités, par application ou utilisateur, avec reconnexion et relecture.\"},\"ru\":{\"name\":\"События реального времени\",\"summary\":\"Ограниченные realtime-события приложения или пользователя с переподключением и повторным чтением.\"}}},\"sourcePath\":\"capabilities/REALTIME_EVENTS.md\",\"selectionMetadata\":{\"schemaVersion\":\"aqteron.builder.selection_metadata.v1\",\"summary\":\"Bounded app/user-scoped live update signals with reconnect and replay.\",\"userNeeds\":[\"update an already-open app quickly when durable shared state changes\",\"show message/status/read-state/presence changes without manual refresh\",\"replay a bounded window of missed live update signals after reconnect\"],\"selectionSignals\":[\"the workflow has multi-tab, multi-device, or multi-user live updates\",\"durable records remain in app_database@1 while realtime only signals changes\",\"bounded long-poll transport with replay is sufficient\"],\"exclusions\":[\"durable business-data history or unbounded event logs\",\"custom WebSocket/SSE servers or arbitrary backend realtime infrastructure\",\"large payloads, files, credentials, secrets, or raw session/user identity transport\"],\"dependencies\":[],\"compatibility\":{\"contracts\":[\"Aqteron PWA v1\"],\"requires\":[],\"conflicts\":[]},\"runtime\":{\"adapterId\":\"realtime_events@1\"},\"availability\":{\"instructionStatus\":\"draft\",\"registryStatus\":\"available\",\"runtimeStatus\":\"runtime_available\",\"builderSelectable\":true,\"instructionVisible\":true,\"entitlementAuthority\":\"aqteron_validator_runtime\",\"notSelectableReason\":null}},\"selfCheckMetadata\":{\"schemaVersion\":\"aqteron.builder.module_self_check.v1\",\"instructionModuleId\":\"aqteron.capability.realtime_events@1\",\"moduleKind\":\"capability\",\"required\":true,\"appliesWhenSelected\":true,\"sourceHeading\":\"Module self-check\",\"checks\":[{\"id\":\"declared_when_helper_used\",\"text\":\"`realtime_events@1` is declared whenever `realtimeEvents` is used\"},{\"id\":\"supported_methods_only\",\"text\":\"only the exact managed `status`, `publish`, `poll`, and `subscribe` helper methods are used\"},{\"id\":\"channels_types_declared\",\"text\":\"every used channel and event type is declared\"},{\"id\":\"bounded_limits\",\"text\":\"each channel has bounded retention, event count, and payload size within the exact platform limits\"},{\"id\":\"app_user_dependency\",\"text\":\"`app_user` channels also declare enabled `app_users@1`\"},{\"id\":\"no_client_authority\",\"text\":\"no client-supplied app/user/subject/session/storage identifier is used as authorization authority\"},{\"id\":\"durable_data_separate\",\"text\":\"durable business records remain in `app_database@1` or another appropriate durable capability\"},{\"id\":\"cursor_reset_refreshes\",\"text\":\"cursor reset causes an authoritative state refresh instead of guessing missing events\"},{\"id\":\"bounded_subscribe_retry\",\"text\":\"subscribe retry uses a bounded exponential backoff with a single in-flight poll\"},{\"id\":\"no_reconnect_amplification\",\"text\":\"reconnect preserves the cursor and does not republish replay/presence events automatically\"},{\"id\":\"presence_ephemeral\",\"text\":\"presence is treated only as an ephemeral hint\"},{\"id\":\"no_sensitive_payloads\",\"text\":\"realtime payloads contain no secrets, credentials, raw session tokens, files, or large/private record bodies\"}]}}",
      "metadata": {
        "runtimeStatus": "runtime_available",
        "builderSelectable": true,
        "instructionVisible": true,
        "entitlementAuthority": "aqteron_validator_runtime",
        "presentation": {
          "locales": {
            "en": {
              "name": "Realtime Events",
              "summary": "Bounded app/user-scoped live update signals with reconnect and replay."
            },
            "fr": {
              "name": "Événements temps réel",
              "summary": "Signaux de mise à jour en temps réel limités, par application ou utilisateur, avec reconnexion et relecture."
            },
            "ru": {
              "name": "События реального времени",
              "summary": "Ограниченные realtime-события приложения или пользователя с переподключением и повторным чтением."
            }
          }
        },
        "sourcePath": "capabilities/REALTIME_EVENTS.md",
        "selectionMetadata": {
          "schemaVersion": "aqteron.builder.selection_metadata.v1",
          "summary": "Bounded app/user-scoped live update signals with reconnect and replay.",
          "userNeeds": [
            "update an already-open app quickly when durable shared state changes",
            "show message/status/read-state/presence changes without manual refresh",
            "replay a bounded window of missed live update signals after reconnect"
          ],
          "selectionSignals": [
            "the workflow has multi-tab, multi-device, or multi-user live updates",
            "durable records remain in app_database@1 while realtime only signals changes",
            "bounded long-poll transport with replay is sufficient"
          ],
          "exclusions": [
            "durable business-data history or unbounded event logs",
            "custom WebSocket/SSE servers or arbitrary backend realtime infrastructure",
            "large payloads, files, credentials, secrets, or raw session/user identity transport"
          ],
          "dependencies": [],
          "compatibility": {
            "contracts": [
              "Aqteron PWA v1"
            ],
            "requires": [],
            "conflicts": []
          },
          "runtime": {
            "adapterId": "realtime_events@1"
          },
          "availability": {
            "instructionStatus": "draft",
            "registryStatus": "available",
            "runtimeStatus": "runtime_available",
            "builderSelectable": true,
            "instructionVisible": true,
            "entitlementAuthority": "aqteron_validator_runtime",
            "notSelectableReason": null
          }
        },
        "selfCheckMetadata": {
          "schemaVersion": "aqteron.builder.module_self_check.v1",
          "instructionModuleId": "aqteron.capability.realtime_events@1",
          "moduleKind": "capability",
          "required": true,
          "appliesWhenSelected": true,
          "sourceHeading": "Module self-check",
          "checks": [
            {
              "id": "declared_when_helper_used",
              "text": "`realtime_events@1` is declared whenever `realtimeEvents` is used"
            },
            {
              "id": "supported_methods_only",
              "text": "only the exact managed `status`, `publish`, `poll`, and `subscribe` helper methods are used"
            },
            {
              "id": "channels_types_declared",
              "text": "every used channel and event type is declared"
            },
            {
              "id": "bounded_limits",
              "text": "each channel has bounded retention, event count, and payload size within the exact platform limits"
            },
            {
              "id": "app_user_dependency",
              "text": "`app_user` channels also declare enabled `app_users@1`"
            },
            {
              "id": "no_client_authority",
              "text": "no client-supplied app/user/subject/session/storage identifier is used as authorization authority"
            },
            {
              "id": "durable_data_separate",
              "text": "durable business records remain in `app_database@1` or another appropriate durable capability"
            },
            {
              "id": "cursor_reset_refreshes",
              "text": "cursor reset causes an authoritative state refresh instead of guessing missing events"
            },
            {
              "id": "bounded_subscribe_retry",
              "text": "subscribe retry uses a bounded exponential backoff with a single in-flight poll"
            },
            {
              "id": "no_reconnect_amplification",
              "text": "reconnect preserves the cursor and does not republish replay/presence events automatically"
            },
            {
              "id": "presence_ephemeral",
              "text": "presence is treated only as an ephemeral hint"
            },
            {
              "id": "no_sensitive_payloads",
              "text": "realtime payloads contain no secrets, credentials, raw session tokens, files, or large/private record bodies"
            }
          ]
        }
      },
      "createdAt": "2026-09-21T05:40:00.000Z",
      "updatedAt": "2026-09-22T04:20:00.000Z"
    },
    {
      "capabilityKey": "web_parser@1",
      "instructionModuleId": "aqteron.capability.web_parser@1",
      "instructionModuleVersionId": "aqteron.capability.web_parser@1@0.1.4",
      "registryStatus": "available",
      "displayName": "Web Parser",
      "summary": "Bounded readable-text parsing for explicitly approved public domains.",
      "metadataJson": "{\"runtimeStatus\":\"runtime_available\",\"builderSelectable\":true,\"instructionVisible\":true,\"entitlementAuthority\":\"aqteron_validator_runtime\",\"presentation\":{\"locales\":{\"en\":{\"name\":\"Web Parser\",\"summary\":\"Bounded readable-text parsing for explicitly approved public domains.\"},\"fr\":{\"name\":\"Analyseur web\",\"summary\":\"Extraction limitée de texte lisible depuis des domaines publics explicitement approuvés.\"},\"ru\":{\"name\":\"Веб-парсер\",\"summary\":\"Ограниченное извлечение читаемого текста с явно разрешённых публичных доменов.\"}}},\"sourcePath\":\"capabilities/WEB_PARSER.md\",\"selectionMetadata\":{\"schemaVersion\":\"aqteron.builder.selection_metadata.v1\",\"summary\":\"Bounded readable-text parsing for explicitly approved public domains.\",\"userNeeds\":[\"read sanitized text from approved public HTTP(S) pages\",\"extract readable text from a specific public URL\",\"use public web text inside an Aqteron workflow\"],\"selectionSignals\":[\"live generation context marks this module usable for the account\",\"source pages are public, readable, and approved\",\"readable_text output is sufficient\"],\"exclusions\":[\"login-only, private, internal, localhost, or metadata URLs\",\"broad crawling, screenshots, binary downloads, raw HTML execution, or browser automation\"],\"dependencies\":[],\"compatibility\":{\"contracts\":[\"Aqteron PWA v1\"],\"requires\":[],\"conflicts\":[]},\"runtime\":{\"adapterId\":\"web_parser@1\"},\"availability\":{\"instructionStatus\":\"draft\",\"registryStatus\":\"available\",\"runtimeStatus\":\"runtime_available\",\"builderSelectable\":true,\"instructionVisible\":true,\"entitlementAuthority\":\"aqteron_validator_runtime\",\"notSelectableReason\":null}},\"selfCheckMetadata\":{\"schemaVersion\":\"aqteron.builder.module_self_check.v1\",\"instructionModuleId\":\"aqteron.capability.web_parser@1\",\"moduleKind\":\"capability\",\"required\":true,\"appliesWhenSelected\":true,\"sourceHeading\":\"Module self-check\",\"checks\":[{\"id\":\"workflow_needs_public_text\",\"text\":\"the user workflow genuinely needs public readable text\"},{\"id\":\"requested_domains_declared\",\"text\":\"every requested domain is explicitly declared\"},{\"id\":\"readable_text_only\",\"text\":\"only `readable_text` is requested\"},{\"id\":\"no_login_or_auth_forwarding\",\"text\":\"no login/session/cookie/Auth forwarding is attempted\"},{\"id\":\"no_private_targets\",\"text\":\"no private/internal/localhost/IP target is accepted\"},{\"id\":\"no_direct_scraping\",\"text\":\"no direct cross-origin scraping/headless crawling is implemented\"},{\"id\":\"declaration_request_agree\",\"text\":\"capability declaration and request URL agree\"},{\"id\":\"platform_errors_user_facing\",\"text\":\"platform errors are shown in user-facing form\"}]}}",
      "metadata": {
        "runtimeStatus": "runtime_available",
        "builderSelectable": true,
        "instructionVisible": true,
        "entitlementAuthority": "aqteron_validator_runtime",
        "presentation": {
          "locales": {
            "en": {
              "name": "Web Parser",
              "summary": "Bounded readable-text parsing for explicitly approved public domains."
            },
            "fr": {
              "name": "Analyseur web",
              "summary": "Extraction limitée de texte lisible depuis des domaines publics explicitement approuvés."
            },
            "ru": {
              "name": "Веб-парсер",
              "summary": "Ограниченное извлечение читаемого текста с явно разрешённых публичных доменов."
            }
          }
        },
        "sourcePath": "capabilities/WEB_PARSER.md",
        "selectionMetadata": {
          "schemaVersion": "aqteron.builder.selection_metadata.v1",
          "summary": "Bounded readable-text parsing for explicitly approved public domains.",
          "userNeeds": [
            "read sanitized text from approved public HTTP(S) pages",
            "extract readable text from a specific public URL",
            "use public web text inside an Aqteron workflow"
          ],
          "selectionSignals": [
            "live generation context marks this module usable for the account",
            "source pages are public, readable, and approved",
            "readable_text output is sufficient"
          ],
          "exclusions": [
            "login-only, private, internal, localhost, or metadata URLs",
            "broad crawling, screenshots, binary downloads, raw HTML execution, or browser automation"
          ],
          "dependencies": [],
          "compatibility": {
            "contracts": [
              "Aqteron PWA v1"
            ],
            "requires": [],
            "conflicts": []
          },
          "runtime": {
            "adapterId": "web_parser@1"
          },
          "availability": {
            "instructionStatus": "draft",
            "registryStatus": "available",
            "runtimeStatus": "runtime_available",
            "builderSelectable": true,
            "instructionVisible": true,
            "entitlementAuthority": "aqteron_validator_runtime",
            "notSelectableReason": null
          }
        },
        "selfCheckMetadata": {
          "schemaVersion": "aqteron.builder.module_self_check.v1",
          "instructionModuleId": "aqteron.capability.web_parser@1",
          "moduleKind": "capability",
          "required": true,
          "appliesWhenSelected": true,
          "sourceHeading": "Module self-check",
          "checks": [
            {
              "id": "workflow_needs_public_text",
              "text": "the user workflow genuinely needs public readable text"
            },
            {
              "id": "requested_domains_declared",
              "text": "every requested domain is explicitly declared"
            },
            {
              "id": "readable_text_only",
              "text": "only `readable_text` is requested"
            },
            {
              "id": "no_login_or_auth_forwarding",
              "text": "no login/session/cookie/Auth forwarding is attempted"
            },
            {
              "id": "no_private_targets",
              "text": "no private/internal/localhost/IP target is accepted"
            },
            {
              "id": "no_direct_scraping",
              "text": "no direct cross-origin scraping/headless crawling is implemented"
            },
            {
              "id": "declaration_request_agree",
              "text": "capability declaration and request URL agree"
            },
            {
              "id": "platform_errors_user_facing",
              "text": "platform errors are shown in user-facing form"
            }
          ]
        }
      },
      "createdAt": "2026-09-16T05:00:00.000Z",
      "updatedAt": "2026-09-16T05:00:00.000Z"
    },
    {
      "capabilityKey": "webrtc_signaling@1",
      "instructionModuleId": "aqteron.capability.webrtc_signaling@1",
      "instructionModuleVersionId": "aqteron.capability.webrtc_signaling@1@0.1.6",
      "registryStatus": "available",
      "displayName": "WebRTC Signaling",
      "summary": "Short-lived app-scoped signaling for browser peer-to-peer WebRTC setup.",
      "metadataJson": "{\"runtimeStatus\":\"runtime_available\",\"builderSelectable\":true,\"instructionVisible\":true,\"entitlementAuthority\":\"aqteron_validator_runtime\",\"presentation\":{\"locales\":{\"en\":{\"name\":\"WebRTC Signaling\",\"summary\":\"Short-lived app-scoped signaling for browser peer-to-peer WebRTC setup.\"},\"fr\":{\"name\":\"Signalisation WebRTC\",\"summary\":\"Signalisation temporaire propre à l'application pour établir des connexions WebRTC pair à pair.\"},\"ru\":{\"name\":\"Сигналинг WebRTC\",\"summary\":\"Краткоживущий сигналинг приложения для установки браузерных WebRTC-соединений peer-to-peer.\"}}},\"sourcePath\":\"capabilities/WEBRTC_SIGNALING.md\",\"selectionMetadata\":{\"schemaVersion\":\"aqteron.builder.selection_metadata.v1\",\"summary\":\"Short-lived app-scoped signaling for browser peer-to-peer WebRTC setup.\",\"userNeeds\":[\"coordinate browser peer-to-peer audio, video, or data channel setup\",\"exchange short-lived WebRTC signaling messages\",\"support real-time peer connection workflows\"],\"selectionSignals\":[\"live generation context marks this module usable for the account\",\"application needs WebRTC signaling with platform-managed relay fallback when direct connectivity fails\",\"short-lived helper-mediated signaling and managed ICE credentials are sufficient\"],\"exclusions\":[\"media recording, SFU/media processing, custom TURN/STUN credential management, or persistent chat storage\",\"storing SDP or ICE payloads in app_database@1\"],\"dependencies\":[],\"compatibility\":{\"contracts\":[\"Aqteron PWA v1\"],\"requires\":[],\"conflicts\":[]},\"runtime\":{\"adapterId\":\"webrtc_signaling@1\"},\"availability\":{\"instructionStatus\":\"draft\",\"registryStatus\":\"available\",\"runtimeStatus\":\"runtime_available\",\"builderSelectable\":true,\"instructionVisible\":true,\"entitlementAuthority\":\"aqteron_validator_runtime\",\"notSelectableReason\":null}},\"selfCheckMetadata\":{\"schemaVersion\":\"aqteron.builder.module_self_check.v1\",\"instructionModuleId\":\"aqteron.capability.webrtc_signaling@1\",\"moduleKind\":\"capability\",\"required\":true,\"appliesWhenSelected\":true,\"sourceHeading\":\"Module self-check\",\"checks\":[{\"id\":\"declared_when_helper_used\",\"text\":\"the capability is declared if signaling helper is used\"},{\"id\":\"signaling_not_database_persisted\",\"text\":\"signaling data is not persisted in `app_database@1`\"},{\"id\":\"no_custom_signaling_route\",\"text\":\"no private/custom signaling server route is invented\"},{\"id\":\"bounded_payload_and_ttl\",\"text\":\"payload size and TTL are bounded\"},{\"id\":\"managed_turn_media_boundary\",\"text\":\"media remains browser WebRTC traffic; managed TURN is only an encrypted-packet relay and is not recording or media processing\"},{\"id\":\"managed_turn_helper_only\",\"text\":\"ICE configuration comes only from the platform helper; no hardcoded relay credentials or routes are embedded\"},{\"id\":\"managed_turn_ephemeral\",\"text\":\"short-lived managed TURN credentials are never persisted and are refreshed for new/recovered calls\"},{\"id\":\"participant_resume_bounded\",\"text\":\"participant recovery uses only the server-issued volatile `resumeToken` and bounded `participant.resume` retries\"},{\"id\":\"app_user_resume_continuity\",\"text\":\"app-user-bound participants cannot resume as a different trusted app user\"},{\"id\":\"no_blind_signal_retry\",\"text\":\"non-idempotent signaling sends are not blindly retried\"},{\"id\":\"recovery_cursor_continuity\",\"text\":\"recovery continues from the last signaling sequence rather than replaying from zero\"},{\"id\":\"visible_failure_states\",\"text\":\"call failure and unsupported-environment states are shown to the user\"}]}}",
      "metadata": {
        "runtimeStatus": "runtime_available",
        "builderSelectable": true,
        "instructionVisible": true,
        "entitlementAuthority": "aqteron_validator_runtime",
        "presentation": {
          "locales": {
            "en": {
              "name": "WebRTC Signaling",
              "summary": "Short-lived app-scoped signaling for browser peer-to-peer WebRTC setup."
            },
            "fr": {
              "name": "Signalisation WebRTC",
              "summary": "Signalisation temporaire propre à l'application pour établir des connexions WebRTC pair à pair."
            },
            "ru": {
              "name": "Сигналинг WebRTC",
              "summary": "Краткоживущий сигналинг приложения для установки браузерных WebRTC-соединений peer-to-peer."
            }
          }
        },
        "sourcePath": "capabilities/WEBRTC_SIGNALING.md",
        "selectionMetadata": {
          "schemaVersion": "aqteron.builder.selection_metadata.v1",
          "summary": "Short-lived app-scoped signaling for browser peer-to-peer WebRTC setup.",
          "userNeeds": [
            "coordinate browser peer-to-peer audio, video, or data channel setup",
            "exchange short-lived WebRTC signaling messages",
            "support real-time peer connection workflows"
          ],
          "selectionSignals": [
            "live generation context marks this module usable for the account",
            "application needs WebRTC signaling with platform-managed relay fallback when direct connectivity fails",
            "short-lived helper-mediated signaling and managed ICE credentials are sufficient"
          ],
          "exclusions": [
            "media recording, SFU/media processing, custom TURN/STUN credential management, or persistent chat storage",
            "storing SDP or ICE payloads in app_database@1"
          ],
          "dependencies": [],
          "compatibility": {
            "contracts": [
              "Aqteron PWA v1"
            ],
            "requires": [],
            "conflicts": []
          },
          "runtime": {
            "adapterId": "webrtc_signaling@1"
          },
          "availability": {
            "instructionStatus": "draft",
            "registryStatus": "available",
            "runtimeStatus": "runtime_available",
            "builderSelectable": true,
            "instructionVisible": true,
            "entitlementAuthority": "aqteron_validator_runtime",
            "notSelectableReason": null
          }
        },
        "selfCheckMetadata": {
          "schemaVersion": "aqteron.builder.module_self_check.v1",
          "instructionModuleId": "aqteron.capability.webrtc_signaling@1",
          "moduleKind": "capability",
          "required": true,
          "appliesWhenSelected": true,
          "sourceHeading": "Module self-check",
          "checks": [
            {
              "id": "declared_when_helper_used",
              "text": "the capability is declared if signaling helper is used"
            },
            {
              "id": "signaling_not_database_persisted",
              "text": "signaling data is not persisted in `app_database@1`"
            },
            {
              "id": "no_custom_signaling_route",
              "text": "no private/custom signaling server route is invented"
            },
            {
              "id": "bounded_payload_and_ttl",
              "text": "payload size and TTL are bounded"
            },
            {
              "id": "managed_turn_media_boundary",
              "text": "media remains browser WebRTC traffic; managed TURN is only an encrypted-packet relay and is not recording or media processing"
            },
            {
              "id": "managed_turn_helper_only",
              "text": "ICE configuration comes only from the platform helper; no hardcoded relay credentials or routes are embedded"
            },
            {
              "id": "managed_turn_ephemeral",
              "text": "short-lived managed TURN credentials are never persisted and are refreshed for new/recovered calls"
            },
            {
              "id": "participant_resume_bounded",
              "text": "participant recovery uses only the server-issued volatile `resumeToken` and bounded `participant.resume` retries"
            },
            {
              "id": "app_user_resume_continuity",
              "text": "app-user-bound participants cannot resume as a different trusted app user"
            },
            {
              "id": "no_blind_signal_retry",
              "text": "non-idempotent signaling sends are not blindly retried"
            },
            {
              "id": "recovery_cursor_continuity",
              "text": "recovery continues from the last signaling sequence rather than replaying from zero"
            },
            {
              "id": "visible_failure_states",
              "text": "call failure and unsupported-environment states are shown to the user"
            }
          ]
        }
      },
      "createdAt": "2026-09-16T05:00:00.000Z",
      "updatedAt": "2026-09-22T04:20:00.000Z"
    }
  ]
}