SDK Engine and Flutter

This page describes the integration tomorrow's Engine and Flutter work should follow. It is not an installable SDK.

Implemented contract

  1. Authenticate with a Sanctum token that has registry:read or registry:write.
  2. Browse GET /api/v1/registry/packages or the public /registry pages.
  3. Resolve POST /api/v1/registry/resolve. The lock records exact versions, manifest digests, artifact digests, edges, decisions, and resolver version 1.0.0.
  4. Fetch the manifest and artifact. Compare the bytes with the lock digests. Do not trust a guessed storage URL.
  5. Read trust.state. unsigned means no signature. publisher_signed or registry_attested means the Ed25519 signature matched. Neither state means the package is safe.

Package format

Manifest schema version is 1. Package types include plugin, cue, sequence, program, studio-template, controller-map, and experience. Capabilities are provides and requires. Permissions are requests and are not granted by publication. Composition references use Source, Cue, Sequence, Program, Schedule, and Studio as contract kinds. Playback is not executed here.

Locks

A lock does not change when a package subscription notices a newer release. Subscriptions are separate from billing subscriptions and from content notifications.

Sample

The checked-in sample is contracts/samples/v1/registry-plugin. Publish it from a package named confetti with the registry sample button. It is a registry sample, not a working Engine plugin.

Not implemented

There is no Flutter package and no Engine runtime in this repository tonight. Do not treat these docs as an SDK release.