Recover, verify, run
Recover and mount a verified work.
Storage supplies exact bytes through one or more carriers. The viewer resolves the declared graph, enforces encoded and decoded limits, verifies commitments, and only then mounts the work inside an isolated runtime.
Data and state model
One work is a committed graph, not a single trusted URL.
Manifest
keel-manifest@2 commits entrypoint, ordered resources, source fallbacks, decoded integrity, runtime engine/capabilities, determinism, viewer binding, revision, and conventional metadata.
Resource graph
The boot shell is small, uncompressed HTML. Its digest-bound resource graph contains scripts, reusable onchain modules, assets, WASM, and data; heavy child resources may be compressed and are exposed only after stored-byte, decompression, length, and decoded-digest checks.
Shared codecs and runtimes
Gzip and Deflate use the shell's capability-checked browser decoder. Brotli requires an exact declared KEEL decoder module. For small p5 works, KEEL recommends the once-per-chain Gzip p5 fragment: the creator root references the shared shell and p5 objects and publishes only the small creator entry slot.
Presentation
Collection/token and active presentation select the exact manifest, object/viewer revisions, seed, loadout, runtime context, and optional links used for this render.
Runtime policy
Effective capability is the intersection of app, manifest, module, and host allow-lists minus every deny. Wallet intents and host operations remain separate symbolic capability families.
Reads, writes, and authority
The privileged host and untrusted child have deliberately different jobs.
Host reads
Resolve collection/presentation state, manifest, registries, object descriptors, carriers, chunks, graph children, links, seeds, equipment/stake context, module/plugin state, and declared external sources.
Host verification
Bound encoded bytes, decompress, bound decoded bytes, verify decoded length/digest, reassemble ordered composites, verify aliases/context, and expose only accepted local bytes.
Child reads
Creator code reads frozen __KEEL_CONTENT__, __KEEL_RUNTIME__, and bounded context in an opaque-origin sandbox. It has no cookies, raw RPC, ambient public network, or injected provider.
const mounted = mountArtifact(container, artifact, {
deterministicViewport: "scale",
});Write handoff
A child may request a declared symbolic operation. The host validates source/session/schema/capability, derives target/calldata/value from verified code and fresh state, simulates, asks the wallet, and verifies receipt/postcondition.
Failure and security boundaries
Correctly hashed HTML, JavaScript, SVG, WASM, fonts, models, audio, and video remain hostile input.
No runtime network fallback
The gateway exposes only exact verified aliases. A failed source may move to another declared byte-identical carrier, but the child cannot fetch an undeclared substitute.
No ambient wallet
The sandbox never receives the provider. Raw target, ABI, selector, calldata, value, navigation, and approval requests from creator code are rejected.
Replay is bounded, not magical
Replay mode pins seed, PRNG, viewport, DPR, clock, locale, timezone, viewer, block, and dynamic overlays where declared. It does not promise universal pixel identity across every engine.
Bridge inputs are hostile
Source window, origin policy, exact schema, message depth/size, dangerous keys, session registration, replay floor, capability, and operation are checked before dispatch.
Storage and carrier realizations
Carriage affects cost and availability. Integrity remains the decoded commitment.
Ethereum / KeelHold
Ingot-backed chunks, leaf objects, and balanced recursive composites support immutable reconstruction. Those objects can feed token and presentation interfaces as well as committed harness outputs.
Source · Recorded testnet deployment
keel-contracts/modules/keel-hold/deployments/11155111.json ↗Tezos / chunk store and OnchFS
The native lane stores chunks once, exposes standard-compatible files/directories, and adds append-only Keel object bindings. Current release proof is local/mockup.
Source · Browser-proven locally
vault-tezos/contracts/keel_chunk_store.py; keel_onchfs_store.py; scripts/test-local.shCanonical carriers and additional sources
The current KeelCarrier kinds are keel, onchfs, ipfs, and https. IPNS and Arweave are additional viewer source or gateway schemes, not KeelCarrier variants. Every retrieved byte must still satisfy its committed digest; availability is measured separately.
Inline, Hybrid, and IPFS are read paths
Inline returns the complete onchain-assembled data:text/html animation_url with no gateway, IPFS, /content, or RPC fetch. Hybrid can still be fully native KEEL storage: its boot shell resolves exact objects through an RPC reader. IPFS is a separate explicit choice and is never inferred from Hybrid.
Compress the graph, not the boot shell
The Solidity builder reads the root HTML directly; it does not decompress Brotli. A committed browser/WASM decoder verifies and expands compressed child modules and assets. Inline is recommended only after the complete document passes the 2 MB reconstruction and 30M-gas public-RPC read gates.
SDK and Studio surfaces
The same verification contract is used by libraries, Studio, and portable hosts.
SDK
@keel/sdk/presentation publishes the shared Boot shell, Resource graph, Browser decoder, Inline, Hybrid, and IPFS language plus the fail-closed Inline assessment. @keel/viewer supplies readers, resolver, sandbox, mount, bridges, capability policy, and verification state; @keel/protocol supplies manifest and integrity rules.
Studio
Content, on-chain, contract-call, manifest, presentation, Tezos view, and viewer context routes perform bounded host work. The index remains a discovery accelerator rather than a render root.
Exact evidence
Tests are split between pure resolution, adversarial boundaries, browser mounting, chain storage, and Tezos mockup reconstruction.
Viewer and protocol
Resolution, readers, sandbox, browser, capability, host bridge, presentation bridge, adversarial boundary, content cache, and frozen datasets have focused SDK suites.
EVM storage
Hold, flat reads, Index, harness gas, and tokenURI gas have focused Foundry suites plus a recorded Sepolia module deployment.
Tezos browser
The local gate compiles SmartPy, runs shared vectors and Octez mockup operations, builds the interactive ZIP, and requires Chromium verification. It explicitly labels the positive lane as mockup replay.
Source
vault-tezos/README.md; scripts/test-local.sh; scripts/test-interactive-browser.mjs
