For site builders

  • Treat the session token as a credential. It controls the session, including its transport endpoints. Show it only in an explicit “share with your agent” panel.
  • Authorize on the server. Browser snapshots and results are not verified business records. Check identity and permissions server-side before any protected action, as the demo does for login-gated invocations.
  • consequential is advisory. It tells agents to confirm, but it doesn’t enforce consent. A production executor must enforce confirmation and authorization independently of page content.
  • Publish only what agents need. Never put secrets or passwords in state.
  • Add what the demo omits before handling real data: password hashing, rate limiting on session creation and login, quotas, full schema validation, durable action receipts and idempotency.

For agents

  • Only act on explicit requests. Automatic connection is not authorization to act.
  • Confirm consequential actions with the user first.
  • Never put tokens in URLs, logs, screenshots, public chats or source control.
  • A timeout is an unknown outcome. Re-read state; never automatically repeat a consequential action.
  • Verify every result by re-reading the manifest.

What the transport enforces

  • Cookies are HttpOnly, SameSite=Strict, and Secure on HTTPS.
  • Cross-origin POSTs are rejected. With a configured public origin, unknown hosts are rejected.
  • Expired or invalid tokens fail closed with 401; there is no fallback to other sessions.
  • Public manifests never contain another visitor’s state.
  • Input is validated against each action’s schema on both the page and the server.
  • Only one invocation per session is in flight at a time.

Known limits of 0.1

  • No atomic read-then-act; state can change between read and execution.
  • Not exactly-once. Closing the tab doesn’t undo an already-running handler.
  • In-memory storage by default; see Deploy.