Documentation · Messaging & reliability
  1. Documentation overview
  2. Core concepts
  3. Protocol Line
  4. Foundation
  5. Identity
  6. Pairwise protection
  7. Messaging & reliability
  8. HTTPS transport
  9. Groups & federation
  10. Verification
  11. Governance & license

Messaging and reliability: meaning beyond delivery

Generic Messaging defines protected records and attachments; Reliable Exchange preserves stable intent and advances finality only from authenticated Endpoint confirmation.

Generic Messaging

The protected application-neutral record layer defines exactly six classes: event, request, response, error, cancel, and streamChunk. Product commands and Station operations are not core message kinds; application meaning stays in bounded opaque payload bytes and namespaced extensions.

Resumable attachments

Attachment declarations fix content identity and chunk geometry before transfer. Receive state is bounded and deterministic; conflicting chunks, invalid geometry, unsupported critical extensions, and ambiguous encodings fail without partial semantic advance.

Reliable Exchange

A stable Protected Intent binds the logical Message identity, application idempotency input, exact user payload, content type, and any complete attachment or Group commitment. Retry on one Route reuses the exact retained protected packet. A Route change may re-protect the same intent but cannot create another authorization or effect.

Endpoint confirmation controls finality

A Station receipt, queue state, lease, timestamp, or delivery claim is only a transport hint. Endpoint Accepted requires the exact authenticated confirmation. Effect Completed additionally requires authenticated success and result binding.

Restart convergence

Send commits the advanced snapshot and retry packet before emission. Restart restores the complete monotonic snapshot; rollback or conflicting idempotency input is terminal and produces no packet or effect. The application still owns local effect idempotency.