For site builders
- Treat the session token as a credential. It controls the session, including its transport endpoints. Show it only in an explicit “share with your agent” panel.
- Authorize on the server. Browser snapshots and results are not verified business records. Check identity and permissions server-side before any protected action, as the demo does for login-gated invocations.
consequentialis advisory. It tells agents to confirm, but it doesn’t enforce consent. A production executor must enforce confirmation and authorization independently of page content.- Publish only what agents need. Never put secrets or passwords in
state. - Add what the demo omits before handling real data: password hashing, rate limiting on session creation and login, quotas, full schema validation, durable action receipts and idempotency.
For agents
- Only act on explicit requests. Automatic connection is not authorization to act.
- Confirm consequential actions with the user first.
- Never put tokens in URLs, logs, screenshots, public chats or source control.
- A timeout is an unknown outcome. Re-read state; never automatically repeat a consequential action.
- Verify every result by re-reading the manifest.
What the transport enforces
- Cookies are
HttpOnly,SameSite=Strict, andSecureon HTTPS. - Cross-origin
POSTs are rejected. With a configured public origin, unknown hosts are rejected. - Expired or invalid tokens fail closed with
401; there is no fallback to other sessions. - Public manifests never contain another visitor’s state.
- Input is validated against each action’s schema on both the page and the server.
- Only one invocation per session is in flight at a time.
Known limits of 0.1
- No atomic read-then-act; state can change between read and execution.
- Not exactly-once. Closing the tab doesn’t undo an already-running handler.
- In-memory storage by default; see Deploy.