OPEN SOURCE · THE WEB 4 STACK

The spec is open.
The network is a product.

Everything a stranger needs to check our claims or build against us ships in the open under Apache-2.0: the manifest format, the conformance suite, the SDK, the settlement verifier, the ledger rules. The services that run them live — the mesh, the books, the floor — are the product. That line is stated here once and holds everywhere.

# don't take our word for any of it
npx @flashyos/verify

This page is a view of one document. /.well-known/open.json carries the same 30 published packages, the 16 held until a first adopter, and every repository with the visibility the register last read for it. Depth per tool, with the edge cases written down, is flashy.tools.

The Web 4 stack

The open formats above are rungs of a larger map. The agentic internet — the web of the Web 4 era GDA Group defines — is a stack of open protocols through which software agents discover, identify, authorize, trust, transact with and audit one another. Each layer answers one question, and each is a spec plus an implementation with its own repository. The whole map, re-measured per repo, is the Web 4 hub; the nine layers, rendered from the machine-readable web4/1 map this page reads rather than restates:

01identityWho are you?delegation/1
flashyid-spec →flashyid (not yet public)
02graphWhat exists?graph/1 · realm/1
agentgraph →therealm (not yet public)
03discoveryWho can accomplish this intent?intent/1
intent-spec →intentmesh (not yet public)
04trustShould I deal with you?trust/1 · ritual/1
magician (not yet public)Rites-Network (not yet public)trustgraph (planned)
05gatewayHow do I connect to the old web?agent/1 · agent-dns/1
agent-wellknown →agent-dns →bastion →
06representationHow is the org shown to machines?aao/0.1
aao (not yet public)
07executionHow does it operate?
flashyos (not yet public)flashyos-spec →flashyos-tools →agentfile →
08commerceHow does value move?pay-policy/1
agentpay →flashyos-wdk →flashy-rails (not yet public)flashy-ledger →flashy-contracts (not yet public)
09auditWhat happened?action-ledger/1 · chronicle/1
agentledger (planned)chronicle (not yet public)flashy-network (not yet public)

A repository is linked only when the register has read it as public; the rest are named and not linked, because a link a stranger cannot open is a claim. The machine twin is served at /.well-known/stack.json.

The wire formats

The standard is a handful of on-the-wire contracts, each with a version in its name and a normative home. All Apache-2.0 — fork them, ship a competing implementation, run the suite against your own register. What turns a prose spec into testable interop is a portable conformance suite: language-neutral vectors with expected verdicts, so a parser in any language can prove it accepts and rejects the same documents ours does. 7 of 16 ship one today; the rest say so rather than pretend. The register of every format, with its profile and schema, is /protocols.

flashyos/1The handshakeportable suite ✓

The one file a stranger reads first — who you are, and where the rest of your record lives

schema →conformance suite →read more →
aao/0.1The charterportable suite ✓

An agent workforce declared the way a cap table declares ownership — who may do what, and who answers for it

schema →conformance suite →read more →
directory/1The directoryportable suite ✓

One record per real thing, merged across an estate, with consent as a signature rather than a policy

spec →schema →conformance suite →read more →
countersign/1Countersignsuite: not yet

A countersignature from the party a claim is about — checkable offline from two published keys, by anyone, forever

spec →schema →packages/countersign/conformance/suite.json exists but declares conformance: 'directory/1' — it checks the directory/1 rules this package validates against, not a countersign/1-specific suite covering delegation, the audit grades or key rotation. Listing it here would be the suite claiming a profile it does not declare.read more →
frontdoor/1The front doorportable suite ✓

Which lanes you open to strangers, what you ask at each, and what you owe in return

spec →schema →conformance suite →read more →
shipped/1The shiplogportable suite ✓

One sealed entry per thing that shipped — dated, attributed, and checkable by a stranger

spec →conformance suite →read more →
backlog/1The backlogportable suite ✓

What an organisation intends, published the way facts are — and decaying, so it cannot lie by inertia

spec →conformance suite →read more →
checkpoint/1The checkpointportable suite ✓

One RFC 6962 root over everything you have sealed, recomputable by anyone, holding no data itself

spec →conformance suite →read more →
mail/1The mail recordsuite: not yet

What an organisation sent — lane, disposition, counterparty domain, time — and nothing a message was about

spec →What a second implementer needs vectors for here is the PROJECTION — how a small counterparty folds into other, and where totals are computed relative to that fold. The differential corpus in tools/vendored-mail.test.mjs exercises exactly that against two implementations, but it is a repo-level gate rather than a portable suite in the shape the other formats ship, and calling it one would be the overstatement the conformance programme argues against.read more →
holding/1The holding registersuite: not yet

What happened to the positions an office holds — transitions, never states, so a correction is an entry rather than an edit

spec →schema →packages/holding/conformance/corpus.json is a differential corpus — documents the TypeScript and vendored checkers must agree about — not a published suite in the portable shape the other formats ship. Calling it one here would be the exact overstatement the conformance programme argues against.read more →
playbook/1The playbooksuite: not yet

How two organisations actually run a thing together — named roles, ordered steps, and the evidence each step owes

spec →schema →The schema settles structure; what a second implementer would need vectors for is instantiation — how {a} and {b} resolve on an `each` step versus a named-role one — and those vectors do not exist yet.read more →
contract/1The contractsuite: not yet

A playbook instance with every party’s human consent, sealed, and countersigned by every other party — a profile over formats that already exist, not a package

spec →schema →The profile computes no hash and verifies no signature — both are injected — so a portable suite would have to carry a sealed, countersigned instance produced by two real organisations, and none exists yet. That instance is the first-adopter condition, not a fixture somebody generates.read more →
action/1The action claimsuite: not yet

What one step of work leaves behind — actor, authority, input, tool, timestamp, output — sealed through the one canonicalisation and re-derivable offline

schema →The schema and the validator are held to each other by a differential test in the package; language-neutral golden vectors with a sealed hash per claim are the next step and do not exist yet, for the same reason receipt/1 ships none.read more →
delivery/1The delivery notesuite: not yet

What an organisation handed over, to whom, and against which agreement

spec →schema →Adopted by one property of twelve. A portable suite is worth writing when a second implementer exists to run it; today it would only ever be run by us.read more →
bolt/1The shardsuite: not yet

One word per property and a published commitment over the set — verified in the finder’s own browser, with no server behind it

spec →The only conformance question a second implementer has is whether their sha256 over the ordered set matches the published commitment, and the commitment itself is that vector.read more →
rwa/1The asset recordsuite: not yet

Assets an organisation holds and the obligations it has issued against them, denominated in a unit that already circulates

spec →schema →Draft. The schema settles structure; a portable suite is worth writing once the format is out of draft and a second implementer exists to run it.read more →

Run any format's suite against your own parser: npx @flashyos/conformance yourdomain.com --level 2 grades a live domain; the per-format suites above check an implementation offline.

Packages · 30 published

@flashyos/boltnpm install @flashyos/bolt

One secret, split across an estate, checked in the finder’s own browser

@flashyos/artifactnpm install @flashyos/artifact

A dated public commitment to content nobody can read yet

@flashyos/aaonpm install @flashyos/aao

The manifest format an agent workforce is declared in

@flashyos/agentnpx @flashyos/agent init

Four lines from a running agent to a visible one

@flashyos/mcpnpx @flashyos/mcp --print-config

The mesh as MCP tools, in one config block

@flashyos/create-mesh-agentnpx @flashyos/create-mesh-agent .

A working mesh agent scaffolded into your repo

@flashyos/create-mesh-nodenpm create @flashyos/mesh-node -- yourdomain.com --email you@org.com

One command from a domain to a node the mesh can see and grade

@flashyos/conformancenpx @flashyos/conformance yourdomain.com

Three levels, and only the third is ours to grant

@flashyos/verifynpx @flashyos/verify

Recompute every hash we publish, and check we are not lying

@flashyos/canonnpm i @flashyos/canon

A lockfile for facts

@flashyos/countersignnpx @flashyos/countersign

A claim about you is not true until you sign it

@flashyos/directorynpm install @flashyos/directory

One record per real thing, merged across an estate

@flashyos/backlognpm install @flashyos/backlog

What an organisation intends, published the way facts are

@flashyos/shiplognpm install @flashyos/shiplog

What you shipped, sealed so a stranger can check it

@flashyos/checkpointnpm install @flashyos/checkpoint

One root over everything you have sealed, recomputable by anyone

@flashyos/pagenpm install @flashyos/page

One page, one card, one claim — written by the same call that sets the title

@flashyos/assetmeshnpm install @flashyos/assetmesh

An asset does not need its own market. It needs a unit somebody already holds

@flashyos/deliverynpm install @flashyos/delivery

The rungs between a merged commit and a thing somebody has

@flashyos/playbooknpm install @flashyos/playbook

A way organisations work together, as a document rather than code

@flashyos/meshnpx @flashyos/mesh status

The checklist for joining, so the sequence is not in somebody’s head

@flashyos/eslint-confignpm install -D @flashyos/eslint-config

The estate’s shared lint base, so a rule is argued once

@flashyos/holdingnpm install @flashyos/holding

What happened to the positions an office holds, as a log

@flashyos/mailnpm install @flashyos/mail

The record of what an organisation sent, carrying none of it

@flashyos/dialectsnpx @flashyos/dialects

One charter, many dialects — and a refusal to emit a surface you do not serve

@flashyos/frontdoornpx @flashyos/frontdoor

Which lanes you open, what you ask, and what you owe

@flashyos/llms-txtnpx @flashyos/llms-txt check https://flashyos.com

The machine-readable front door, parsed and checked

@flashyos/llm-gatewaynpm install @flashyos/llm-gateway

One inference seam, several providers behind it

@flashyos/wallet-wdknpm install @flashyos/wallet-wdk

Governed spending for agents on Tether WDK: the record, the verdict, the verifiers

@flashyos/signernpm install @flashyos/signer

The one process that holds a seed, and it re-derives before it signs

@flashyos/wdknpm install @flashyos/wdk

The agent object: identity, authority, wallet, memory and partners behind one interface

Held · 16 until a first adopter

Apache-2.0 in the tree and deliberately off every registry. A format is published on its first adopter, never before: a package with no user outside this estate would be a promise about stability nobody has tested. Each one carries the reason it waits.

@flashyos/alchemyA format is unpublished until its first adopter — the estate's own rule, which reward/1, wallet/1, ritual/1, pulse/1 and deploy/1 all obey. alchemy/1 has exactly one world today and it is ours, so a registry listing would be adoption theatre. It publishes on the day a second party writes a ruleset, which is also the day the vocabulary stops being ours alone and starts being worth agreeing on.
@flashyos/computeNot published, and the reason is the format's own subject. compute/1 records the inference compute an AAO spent per initiative, and the estate has spent none through the seam yet — LLM_PROVIDER has never been flipped to gatewayz outside tests, so every history the format would carry today is empty or uncaptured. Publishing a package for a per-initiative compute history when no initiative has captured compute is a registry entry for a thing nobody does, which is the adoption theatre this estate measures elsewhere. The estate's rule for exactly this is written down repeatedly: publication on the first adopter, never before. The vendored emitter travels by file copy, which is how every record format here actually travels, so being unpublished costs an adopter nothing.
@flashyos/definedNot published, and the reason is this family's own rule for formats: publication on the first adopter, never before. No party outside the estate this was written in publishes a defined/1 fragment yet, so a package on a registry would be adoption theatre. The vendored file travels by copy, which is how every record format here actually travels, so being unpublished costs an adopter nothing.
@flashyos/deployNot published, and by the same rule reward/1 carries: publication on the first adopter, never before. deploy/1 is a format and a dependency-free checker meant to be vendored into any repository that serves a domain, and no party outside this estate declares one yet — so a registry entry today would be a package for a thing nobody does, which is the adoption theatre this estate measures elsewhere. Apache rather than AGPL because a checker a party can only run under copyleft is one the parties who most need to declare a deployment cannot embed.
@flashyos/estate-ringNot published, and the reason is the estate's own rule for formats: publication on the first adopter, never before. No organisation outside this estate reads an interlink ring as estate-ring/1 yet, so a package on a registry would be adoption theatre. The vendored emitter travels by copy, which is how every record format here actually travels, so being unpublished costs an adopter nothing; the ring the footer renders is the served document, not the package.
@flashyos/guardianNot published, and the reason is independence as much as adoption: a guardian is only worth anything if it runs somewhere the guarded code cannot reach, and no organisation outside this repository deploys one yet. Publishing the shape before a second deployment exists would be a package for a thing nobody does, which is the adoption theatre this estate measures elsewhere. It becomes public with the first guardian deployed by a party other than the one it guards.
@flashyos/pinnedPublished on the first external adopter, never before — the estate's rule for every record format. pinned/1 is adopted INSIDE the estate today by vendored file copy (flashy.academy's content-graph gate consumes it; flashyos pins its own derived docs through tools/pinned.mjs), which is how every record format here actually travels: node: builtins only, copied byte-for-byte, no install. A registry entry for a standard nobody outside has adopted is the adoption theatre this estate measures against, so it stays private until someone outside asks to install it — at which point being unpublished has cost that adopter nothing.
@flashyos/pulseNot published, and by the same rule deploy/1 carries: publication on the first adopter, never before. pulse/1 is a format and a vendored emitter, and no adopter outside this estate keeps a condition series yet — the command centre reads the workspace directly and the vendored file travels by copy, so publishing now would be a registry entry for a thing nobody does. Apache rather than AGPL because a format for measuring your own estate is worth nothing if the parties measuring theirs cannot embed it.
@flashyos/registerNot published, and the reason is the estate's own rule for formats: publication on the first adopter, never before. No organisation outside this estate publishes a register yet, so a package on a registry would be adoption theatre. The vendored file travels by copy, which is how every record format here actually travels, so being unpublished costs an adopter nothing. The FRAGMENT is served publicly today; that is the document, not the package.
@flashyos/rewardNot published, and the reason is the format's own subject. reward/1 describes entitlements that cannot be paid until a settlement venue exists, and no venue exists — Flashy Finance's shared wallet is the venue and it has not been built. Nothing in this estate emits the format, so publishing it would put a package on a registry for a thing nobody does yet. The estate's rule for exactly this is written down twice: publication on the first adopter, never before. The vendored emitter travels by file copy, which is how every record format here actually travels, so being unpublished costs an adopter nothing.
@flashyos/ritualNot published, and the reason is the estate's own rule for formats: publication on the first adopter, never before. Nothing outside this estate observes a liturgy yet, so a package on a registry would be adoption theatre. The vendored file travels by copy, which is how every record format here actually travels, so being unpublished costs an adopter nothing.
@flashyos/standingNot published, and the reason is doctrine as much as adoption: a trust figure is the most tempting derived field this estate will ever hold, and the decision on who may see one is private-tier, promote-only, refused by name in every validator. No organisation outside this repository computes standing/1 yet, so a registry entry would be adoption theatre; and until the figure's visibility rule has a first adopter, publishing the function invites publishing the number.
@flashyos/tallyNot published, and the reason is the estate's own rule for formats: publication on the first adopter, never before. No organisation outside this estate publishes a tally yet, so a package on a registry would be adoption theatre. The vendored file travels by copy, which is how every record format here actually travels, so being unpublished costs an adopter nothing.
@flashyos/voiceNot published, and the reason is the estate's own rule for formats: publication on the first adopter, never before. gda-group is voice/1's first real adopter and it takes the file by copy, not by installing this package, so a registry listing would be adoption theatre before any second repository has asked for one. The vendored file travels by copy, which is how every convention in this estate actually travels, so being unpublished costs an adopter nothing.
@flashyos/walletNot published, and the reason is the format's own subject. wallet/1 describes a holding that becomes spendable only once a venue declares itself operational and cites an invariant run that passed. Flashy Finance is that venue and it is being built; no fragment in this estate declares an operational one. Publishing the package now would put a wallet contract on a registry ahead of the thing that honours it, which is the failure this format exists to refuse, made one layer up. The estate's rule for exactly this is written down twice: publication on the first adopter, never before. The vendored emitter travels by file copy, which is how every record format here actually travels, so being unpublished costs an adopter nothing.
@flashyos/workflowNot published, and the reason is the estate's rule for formats: publication on the first adopter, never before. workflow/1 is new in V2-D and no organisation outside this repository runs a workflow through it yet; the invoice-to-payment scenario in its own tests is the only adopter. A registry entry for a format nobody runs would be adoption theatre, which the estate measures elsewhere. It becomes public the day a second property executes a definition it did not write.

Repositories

FlashyLabs/agent-dnsApache-2.0

agent-dns/1 — domain→organisation→agent resolution over one DNS TXT record, with a dependency-free reference resolver.

FlashyLabs/agent-wellknownApache-2.0

agent/1 — the /.well-known/agent discovery document: how a site exposes an authenticated, discoverable, payable machine interface.

FlashyLabs/agentfileApache-2.0

agentfile — answer the accountability question about an organisation in ninety seconds.

FlashyLabs/agentgraphApache-2.0

graph/1 — the vendor-neutral spec for the universal graph of the agentic internet: who and what exists, and the evidenced relations between them.

FlashyLabs/agentpayApache-2.0

pay-policy/1 — the vendor-neutral payment-policy abstraction for agents: an allow/deny/escalate evaluator, not a wallet.

FlashyLabs/bastionApache-2.0

Bastion — the gateway that exposes an existing site or API as a secure, authenticated, payable machine interface. In design.

FlashyLabs/conformance-kitApache-2.0

@flashyos/conformance-kit — run a conformance corpus against any executable, in any language.

FlashyLabs/flashy-docsApache-2.0

The documentation hub for the Flashy ecosystem.

FlashyLabs/flashy-examplesApache-2.0

Working examples and tutorials for the estate’s packages.

FlashyLabs/flashy-ledgerApache-2.0

@flashylabs/ledger — the multi-asset ledger other properties post through.

FlashyLabs/flashyid-specApache-2.0

delegation/1 — the vendor-neutral spec, schema, vectors and checker for cryptographically provable delegated authority for agents.

FlashyLabs/flashyos-specApache-2.0

The public home of the estate’s accountability formats — aao/0.1, flashyos/1, directory/1, frontdoor/1 and the rest: spec, schema, conformance corpus and a dependency-free checker per format.

FlashyLabs/flashyos-toolsApache-2.0

@flashyos/tools — small answers to questions that fail silently; the estate’s charter and provisioning tooling.

FlashyLabs/flashyos-wdkApache-2.0

The public mirror of the WDK wallet stack: the extractor packs, the remote-authorization policy, the isolated signer and the agent object.

FlashyLabs/intent-specApache-2.0

The canonical, vendor-neutral home of intent/1 — spec, JSON Schema, conformance vectors and a dependency-free checker.

FlashyLabs/mesh-lintApache-2.0

@flashyos/mesh-lint — a GitHub Action for the checks that fail silently.

FlashyLabs/stack.jsonApache-2.0

web4/1 — the machine-readable index of the Web 4 / agentic-internet stack: one document, a schema and a dependency-free checker.

FlashyLabs/wdk-capability-auditApache-2.0

Scan node_modules for installed @tetherto/wdk-* packages and report the chains each declares, refusing to guess at one it does not recognise.

FlashyLabs/wdk-policy-guardApache-2.0

A spending-policy layer for WDK wallets: grade a transfer against a per-agent envelope and return ALLOW, ESCALATE or DENY, with a reason.

FlashyLabs/wdk-staking-kitApache-2.0

A reference staking primitive for WDK wallets: lock a balance for a fixed term at a published rate; only yield is a real write, on close.

FlashyLabs/web4Apache-2.0

The human front door to the Web 4 stack: the map, the architecture, the principles and the rule for how a new protocol joins.

21 of 39 open-licensed repositories have been read as public. The others are named in the register and not linked here until a reading says a stranger can open them.

Planned, with their status

FlashyLabs/agentfileagentfilenot released

agentfile — answer the accountability question about an organisation in ninety seconds.

Not released. The formats it writes are published and stable; the seven questions and the writer are the work that remains. Nothing here is installable yet.

FlashyLabs/conformance-kit@flashyos/conformance-kitnot released

@flashyos/conformance-kit — run a conformance corpus against any executable, in any language.

Pre-1.0. The line protocol is the part worth freezing and it is deliberately tiny: `{id, set, input, context?}` in, `{id, valid, codes?}` out. It will be locked at 1.0 and has not changed since it was written.

FlashyLabs/flashyos-specnot released

The public home of the estate’s accountability formats — aao/0.1, flashyos/1, directory/1, frontdoor/1 and the rest: spec, schema, conformance corpus and a dependency-free checker per format.

The specifications are not here yet. They are Apache-2.0 today; carrying the packages out of the monorepo they were written in, *with their real commit history*, is a deliberate operation rather than a copy — a chain of title that begins on the day somebody remembered to copy the files is not a chain of title. Until that runs, this repository is the licence, the security policy and the direction.

FlashyLabs/flashyos-tools@flashyos/toolsnot released

@flashyos/tools — small answers to questions that fail silently; the estate’s charter and provisioning tooling.

Pre-1.0. `served` and `reachability` have been running against a thirty-eight repository estate for months; the API is small and unlikely to move, but the version says 0.x until somebody outside that estate has depended on it.

FlashyLabs/mesh-lint@flashyos/mesh-lintnot released

@flashyos/mesh-lint — a GitHub Action for the checks that fail silently.

Not released. The code is here; the distribution is not. The three checks run, are tested against fixtures rather than against the estate that found them, and `action.yml` is a composite action with no build step. What does not exist yet is a published package or a tag — measured 2026-09-23, `@flashyos/mesh-lint` answers 404 on npm and this repository has no tags — so `npx @flashyos/mesh-lint` and `uses: flashylabs/mesh-lint@v1` both fail today. Clone it and run `node src/cli.mjs` until they do. That gap is named here rather than left for the first person who copies a line out of the section above, which is the same defect this package's own `well-known` check exists to find.

Also open

The brand & press kit (marks, lockups, tokens, usage rules — downloadable). The spec page for the format itself lives at /aao, and the naming standard at /standard. Together these packages are the open half of an agent execution protocol; the network that enforces it live is the execution infrastructure.

Every repo we open carries a sealed ⚡ STRIKE — a sha256 commitment whose preimage a finder can hand us, written in that repo's STRIKERS.md. The count is measured at the graph, never typed here.