Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
11 changes: 8 additions & 3 deletions web/content/docs/relayflows/plugins.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -118,7 +118,7 @@ The gallery and the deploy wizard display a tier. **The label is never used to s
| **verified** | bundle `identity.json` keyid matches a publisher key registered in Cloud |
| **community** | anything else |

Babysitter in catalog v3 is **first-party**: its reviewed `v2.0.26` artifact commit is reachable from `AgentWorkforce/flows` main, and the hosted runtime provenance is the published SDK `v2.0.31` release. The label does not widen runtime authority.
Babysitter in plugin catalog v3 and Recommended catalog v4 is **first-party**: its reviewed `v2.0.26` artifact commit is reachable from `AgentWorkforce/flows` main, and the hosted runtime provenance is the published SDK `v2.0.31` release. The Recommended entry makes the blocked extension discoverable alongside Software Garden; the label does not widen runtime authority.

<Note>
`permissions.writes` stays a reviewed declaration labelled UNENFORCED until gate 8. Displaying a first-party or verified badge does not enforce write scope, skip the digest, or route an event the registry does not carry.
Expand All @@ -128,7 +128,7 @@ Babysitter in catalog v3 is **first-party**: its reviewed `v2.0.26` artifact com

`flowPluginBadgeMarkdown()` renders the README form for an extension whose activation gate is ready. `plugin` is appended so repeats survive.

Babysitter's gate requires both `cloud-babysitter-capability-adapter` and `relay-native-existing-session-delivery` to carry a pull request, merge commit, merge time, deployment receipt, and deployment time. Until both proofs are recorded and the gate state is `ready`, `flowPluginInstallHref()` returns `null` and the gallery shows catalog status plus source only.
Babysitter's gate requires `cloud-babysitter-capability-adapter`, `relay-hosted-flow-extension-execution`, and `relay-native-existing-session-delivery` to carry a pull request, merge commit, merge time, deployment receipt, and deployment time. It also requires `liveProof`: an immutable, digest-addressed JSON record from a full `babysit` label-to-existing-session-turn-to-receipt run. The proof pins the pull request, live head, exact label, observation time, and receipt ID, and must postdate every dependency deployment without being future-dated. Until all deployment proofs and that integrated proof are recorded and the gate state is `ready`, `flowPluginInstallHref()` returns `null` and the gallery shows catalog status plus source only.

The catalog itself is versioned JSON, `{version:3, plugins:[{name, description, source:{owner,repo,path}, ref, digest, manifestSha256, compat, runtime, activation, tier, base}]}`. Any public repo with a `flows-plugin.json` remains installable by an explicit source URL; the curated catalog does not advertise an activation route until its dependency gate is satisfied.

Expand All @@ -137,8 +137,13 @@ The code-owned implementation contract binds `cloud-babysitter-capability-adapte
to [Cloud PR #3989](https://github.com/AgentWorkforce/cloud/pull/3989) and
`relay-native-existing-session-delivery` to
[Relay PR #1851](https://github.com/AgentWorkforce/relay/pull/1851). Unrelated PRs
in those repositories cannot satisfy either dependency. A replacement implementation
in those repositories cannot satisfy either registered dependency. A replacement implementation
requires a reviewed code change to this contract.
`relay-hosted-flow-extension-execution` deliberately has no accepted implementation
PR yet. Cloud PR #4002 is a consumer contract, not execution authority, and cannot
satisfy this dependency. Activation therefore remains impossible until the assigned
Relay/Flows owner opens a focused implementation PR and a reviewed catalog change
registers that exact PR before deployment evidence can be admitted.
`pullRequestUrl` must identify a merged PR into the dependency repository's `main`,
with the exact `mergedCommit` and `mergedAt`. `deploymentUrl` must be the canonical
GitHub API deployment URL (`https://api.github.com/repos/OWNER/REPO/deployments/ID`).
Expand Down
13 changes: 10 additions & 3 deletions web/content/docs/relayflows/recommended.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -9,9 +9,15 @@ Recommended flows are maintained starting points. The catalog is public, version

Software Garden is the display name of the first recommended flow. Its stable catalog and authored flow ID is `software-factory`: a GitHub issue starts implementation, deterministic repository checks, adversarial review, and a pull request for a human decision.

The released source uses Claude Code for implementation and review, so catalog version 3 allows and defaults only that harness. A future catalog version can point at a new released source with a different requirement; clients do not rewrite the authored flow.
The released source uses Claude Code for implementation and review, so the Software Garden entry allows and defaults only that harness. A future catalog version can point at a new released source with a different requirement; clients do not rewrite the authored flow.

Software Garden currently supports GitHub repositories. Deploy one listener per repository using the direct-source API below. Babysitter remains a [flow plugin](/docs/relayflows/plugins), not a recommended flow of its own. The catalog carries its immutable artifact and Relayflows SDK 2.0.31 runtime provenance as inert extension metadata; activation stays blocked until the Cloud capability adapter and Relay native delivery both carry merge and deployment evidence.
Software Garden currently supports GitHub repositories. Deploy one listener per repository using the direct-source API below.

## Babysitter

Babysitter is a first-class Recommended entry so its purpose and readiness are visible. It is a [flow plugin](/docs/relayflows/plugins) that extends Software Garden, not a standalone listener: its `kind` is `extension` and its `baseFlowId` is `software-factory`.

The Babysitter detail response carries the exact reviewed extension bundle, immutable artifact digest, manifest digest, and Relayflows SDK 2.0.31 runtime provenance. Discovery does not imply availability. Activation remains blocked, and no activation link is advertised, until the Cloud production host and Relay native existing-session delivery carry exact merge and deployment evidence and the integrated label-to-turn-to-receipt path has an immutable, digest-addressed `liveProof` record.

## Catalog API

Expand All @@ -20,9 +26,10 @@ The stable endpoints are:
```text
GET https://agentrelay.com/api/v1/flows/catalog
GET https://agentrelay.com/api/v1/flows/catalog/software-factory
GET https://agentrelay.com/api/v1/flows/catalog/babysitter
```

The list response starts with `schemaVersion: 1` and `catalogVersion: 3`. Every flow has a stable `id`, its own numeric `version`, display copy, repository-host support, trigger defaults, required/default activation inputs, and an immutable source reference. Optional extension entries are metadata only unless their activation gate is `ready` and every declared dependency has merge and deployment evidence.
The list response starts with `schemaVersion: 1` and `catalogVersion: 4`. Every entry has a stable `id`, its own numeric `version`, display copy, repository-host support, and an immutable source reference. Flow entries carry trigger defaults and activation inputs. Extension entries instead name their base flow and plugin contract. An extension is not activatable unless its gate is `ready` and every declared dependency has merge and deployment evidence.

The catalog does not copy or generate the flow body. `source` names the canonical `AgentWorkforce/flows` owner, repository, path, release tag, full commit SHA, GitHub blob and raw URLs, media type, and SHA-256 content digest. Both URLs contain the commit SHA, never a mutable branch:

Expand Down
Loading
Loading