_meta extension key + the _codebuddy.ai/* extension method._meta Availablecbc --acp initialize / session/new / session/prompt, the client can use a single codebuddy.ai/* _metacbc-tui / cbc-headless / agent-sdk-js-single):src/node/session/process-login-admission-authority.ts — holds the transport credential and principal in-process, and issueMainAdmission() constructs both the admission envelope and its grant in the same place.src/node/session/process-login-acp-admission-service.ts:60-84 — within admitAndActivate(), the metadata is entirely replaced with a ticket produced by the current process. The original comment serves as the contract: "The client _meta does not participate in identity decisions at all."src/e2e/acp-zero-meta-contract.spec.ts — bare stdio NDJSON drives bin/codebuddy --acp,initialize → session/new → session/prompt with zero meta throughout, and directly fail on errors such as "missing ... metadata".session/new_meta['codebuddy.ai/sessionAdmissionV2'] (see runtime-admission-acp-adapter.ts:47-48).ACP Session request is missing sessionAdmissionV2 metadata). That is a private channel, not an ACP protocol requirement —workbuddy-single) andworkbuddy-completion-warm has been changed from the "per-session wire identity envelope" to process-level identity injection —initialize, the daemon passes through _codebuddy.ai/activateWorkbuddyOwnerRuntime_codebuddy.ai/activateCompletionRuntime) injects the owner authorization once, after which within the CLI process.session/new of these two planes no longer carries sessionAdmissionV2 / authSession,runtimeTransportCredential (a transport authentication invariant, verified each time before self-signing)sessionGrantV1 / completionDispatchGrantV1 (§3.1).sessionAdmissionV2 converge to three locations, with only the first still passing through the daemon→CLI wire:workbuddy-host-control-authority.ts);workbuddy-admission-security.ts issueTeammateAdmissionMetadata);issueMainAdmissionMetadata / issueCompletionDispatchMetadata).Annotation | Description |
Public | Public optional extension. The standard ACP plane ( cbc --acp) is visible or optionally carried; its absence does not affect protocol availability; third-party clients can safely read and ignore it as needed. |
Private | A multi-tenant private channel that is produced and consumed only by the session-payload composite root (WorkBuddy daemon ↔ CLI, multi-owner-headless). Third-party ACP clients must not produce these keys; the standard plane never requests them. |
A→C = Agent to Client (response/notification); C→A = Client to Agent (request parameters); Bidirectional = appears in both directions.file:line anchors in this document correspond to the source code at the time of writing (and the most recent review), and are provided only for quick reference;# Run at the root of the genie repository; git grep naturally excludes build artifacts such as node_modules / dist / lib / out-tscgit grep --untracked -hoE "codebuddy\\.ai/[A-Za-z0-9_.-]*" -- 'packages/**/*.ts' 'packages/**/*.tsx' | sort -u | wc -l# => 195 (deduplicated token count)
--untracked is required: without it, only tracked files are counted, and any newly added source files that have not yet been committed will be.-oE does not include /, so _codebuddy.ai/foo is tokenized as codebuddy.ai/foo (with the leading underscore dropped),_codebuddy.ai/session/rollback is tokenized as codebuddy.ai/session. 195 is the number of tokens, not the number of keys,Bucket | Quantity | What It Is | Location in This Document |
A | 142 | Actual _meta extension keys | Section 3 (all listed) |
B | 44 | JSON-RPC extension method/notification names ( _codebuddy.ai/*), with underscores removed by grep. | Section 4 (all listed) |
C | 3 | Namespace prefix / wildcard notation, not a standalone key. | §5.1 |
D | 6 | False positives from product site URL paths ( https://www.codebuddy.ai/...) | §5.2 |
completionDispatchId /.completionExecutionDigest, add sessionGrantV1 / completionDispatchGrantV1);_codebuddy.ai/activateWorkbuddyOwnerRuntime)._ ⇒ extension method (B),. or / ⇒ URL (D), otherwise ⇒ _meta key (A). Then identify the wildcard prefixes that can be followed by / or * (C)._meta Extension Keys (142 Items)Key | Direction | Category | Producer | Consumer | Description |
runtimeAdmission | A→C | Public | CLI, runtime-admission-acp-adapter.ts:10-11,30-39 (initialize response) | daemon on the session-payload side (constructs the envelope accordingly); standard clients can ignore this. | Process admission handshake: schemaVersion / runtimeProfile / runtimeConfigSha256 / processInstanceId / handshakeNonce. Both composition roots send it, and zero-meta e2e uses it to anchor runtimeProfile === 'cbc-headless'. |
sessionAdmissionV2 | C→A | Private | multi-owner issuer (issued out-of-process); the only remaining member of the WorkBuddy family is the host control sidecar ( workbuddy-host-control-authority.ts). | runtime-admission-acp-adapter.ts:47-53,multi-owner-acp-admission-service.ts:164 | Admission envelope for session/new / session/load. If missing, ACP Session request is missing sessionAdmissionV2 metadata is reported. process-login and post-C3 workbuddy-single / completion-warm are all generated and overridden by the CLI, so clients do not need to and should not carry it. |
sessionGrantV1 | C→A | Private | daemon, workbuddy-runtime-admission.ts buildSessionGrantMetadata (added in C3) | workbuddy-single-admission-authority.ts readWorkbuddySessionGrant (assembled only in workbuddy-single) | Non-identity business authorization that still needs to traverse the wire after identity is removed from _meta: canonicalSessionId (the daemon's session primary key, asserted by captureRuntimeBinding to be equal in the report) / environment.values (the only delivery channel for incremental session env on the prewarm hit path) / workspace{root,cwd,allowedRoots}. Does not participate in identity decisions; the standard ACP surface does not read this key. |
completionDispatchGrantV1 | C→A | Private | daemon, workbuddy-runtime-admission.ts buildCompletionDispatchGrantMetadata (added in C3) | workbuddy-single-admission-authority.ts readWorkbuddyCompletionDispatchGrant (assembled only in completion-warm) | per-dispatch execution authorization for completion warm: executionSubPolicyId + its digest / dispatchId / executionDigest / workspace. Identity comes from process-level injection, and the execution ceiling is still issued by the daemon per dispatch; if this key is missing, the system fails closed. |
authSession | C→A | Private | daemon (session-payload identity seed) | acp-agent.ts:2141-2143 → per-session auth holder | { auth: { accessToken, tokenType?, domain?, refreshToken? }, account?: { uid? } }. The account field is always derived from the JWT and never trusts client-reported values. |
productConfig | C→A | Private | daemon( workbuddy-server/src/agent/cli-product-env.ts:170) | acp-agent.ts:2144-2146 | per-session product configuration injection: endpoint / networkEnvironment |
runtimeTransportCredential | Bidirectional | Private | Admission core ( multi-owner-acp-admission-service.ts:38-39, host-teammate-admission-security.ts:41) | Same as above. | One-time credential bound to the transport, used to prove the connection identity during admission. |
runtimeSessionBindingV2 | A→C | Private | multi-owner-acp-admission-service.ts:40-41,workbuddy-session-admission-authority.ts:18 | daemon | exact binding projection returned after successful admission: ownerId / ownerGeneration / canonicalSessionId / sessionGeneration / resourceId |
runtimeBindingToken | C→A | Private | daemon | agent-client-protocol/src/common/runtime-wire-authority.ts:1,acp-agent.ts:2147-2155 | binding token for wire requests; must be a non-empty string, otherwise RUNTIME_BINDING_TOKEN_INVALID is reported. |
runtimeAuthority | Bidirectional | Private | daemon / CLI | runtime-wire-authority.ts:2 | wire fencing authority snapshot (processIncarnation / connectionEpoch / owner / session / run generations); on mismatch, RUNTIME_*_STALE is thrown. |
teamNamespaceActivation | C→A | Public | Injected by the leader when the leader starts a teammate ( host-teammate-launch.ts:138, workbuddy-teammate-launch.ts:124). | teammate subprocess | team namespace activation declaration. Shared by both composition roots, not exclusive to session-payload; third-party clients will not encounter it. Restriction: the only consumption path is the teammate bootstrap startup chain ( teammate-runner.ts:272 reads it from the bootstrap metadata returned by receiveWorkbuddyTeammateBootstrap), not the client _meta on the ACP wire; if a third-party client produces this key on the standard ACP surface, it will not be consumed by any path. |
userinfo | A→C | Public | acp-agent.ts:1963-1974 (authenticate response) | Client UI | Logged-in user information: userId / userName / userNickname / enterpriseId / enterpriseName / authType |
accessToken | - | Private | No producer (does not exist at the protocol level) | - | Appears only in the log redaction coverage test case ( workbuddy-core/.../conversation-file-logger.spec.ts:44): verifies that token keys with namespace prefixes are also [redacted]. Listed here to prevent it from being mistaken as a usable key in the future. |
homeDir | - | Public | Retired | - | Retired dead field; both the producing and consuming code have been physically removed (D6-7): the only hit in the entire repository is the reverse-gate test case settings-persession-invariants.spec.ts:10, which asserts that this key no longer appears in acp-agent.ts — not even a legacy compatibility read side exists, so a client carrying this key will not be read by any path. homeDir is always derived from the JWT (resolveControlledHomeDir). This entry is kept only to prevent the key name from being re-enabled. |
_meta of responses/notifications, and clients can optionally consume them. requestId / messageRequestId /.userMessageId / messageId can also be sent by the client in advance on session/prompt (acp-agent.ts:2925-2938). By default, they are generated by the CLI.Key | Direction | Producer | Description |
requestId | Bidirectional | acp-agent.ts:2925,3412 | Full-link correlation ID of a model request (the key with the highest number of hits) |
messageId | Bidirectional | acp-agent.ts:2937,3349 | Message-level ID |
messageRequestId | Bidirectional | acp-agent.ts:2932,3423 | Correlation ID between message and request |
userMessageId | Bidirectional | acp-agent.ts:2931 | User message ID (also returned in session/prompt responses) |
promptRequestId | Bidirectional | acp-agent.ts:3415-3416 | Business correlation ID generated by Renderer for each send/resend, used for Desktop tracking + Galileo correlation. |
clientRequestId | C→A | Client | Client-defined correlation ID for tool calls ( workbuddy-server/src/session/handlers.ts:1634) |
modelRequestId | A→C | acp-view.ts:694 | Model-side request ID |
traceId | A→C | acp-agent.ts:3075 | CLI-side trace ID |
traceparent | A→C | acp-agent.ts:2866,3429 | W3C traceparent is returned so that the renderer's stream_render span can be attached under prompt.send. |
runId | A→C | acp-agent.ts:263 | run ID of SessionRunStateMachine |
runStateRevision | A→C | acp-agent.ts:262 | revision of the run state snapshot |
agentPhase | A→C | acp-agent.ts:261 | Agent execution phase ( AgentPhaseInfo) |
timestamp | A→C | acp-timestamp-meta.ts:124-128 | Timestamp (this flat key is removed during normalization and handled in a canonical location) |
sendTime | C→A | Renderer | Timestamp of the user's click to send, used for calculating user-perceived TTFT at the message dimension ( galileo-timing-hook.ts:110) |
lfConvId | A→C | Upstream | LF conversation ID (passed through as a flat field, agent-ui/src/adapters/acp-message-accumulator.spec.ts:1132) |
lfConvReqId | A→C | Upstream | LF conversation request ID (same as above) |
Key | Direction | Category | Producer → Consumer | Description |
mode | Bidirectional | Public | acp-agent.ts:2984,3072 | scene mode |
userId | C→A | Public | Renderer → session.meta(acp-agent.ts:2888) | User ID used for event tracking / trace attributes (not involved in identity decisions; identity is determined solely by JWT) |
conversationId | Bidirectional | Public | acp-agent.ts:2889 / workbuddy-app/.../stream-span-manager.ts:144 | Upstream conversation ID |
locale | C→A | Public | acp-agent.ts:2890 (compatible with language) | Language / locale |
expertId | Bidirectional | Public | acp-agent.ts:2891,2987 | expert ID |
expertSelection | A→C | Public | workbuddy-server/.../expert-selection-reminder.ts:7 | Expert selection reminder block flag |
parentSessionId | A→C | Public | acp-protocol.ts:319,342 | Parent session ID of the subagent conversation |
isSubAgent | A→C | Public | acp-protocol.ts:319,342 | Whether it is a subagent session (note that the casing differs from isSubagent below, which is a legacy duplicate). |
isSubagent | A→C | Public | api-schema.ts:1803,use-acp.ts:284 | Whether the tool call is a subagent call |
subagentType | A→C | Public | api-schema.ts:1804 | Subagent type (default: general-purpose) |
isBackground | A→C | Public | api-schema.ts:1805 | Background execution or not |
isPlayground | A→C | Public | stream-span-manager.ts:148 | playground scenario or not |
continue | C→A | Public | acp-agent.ts:2560 | Declare "continue previous conversation" on session/new |
sessionControl | Bidirectional | Public | workbuddy-core/.../conversation-prompt-operations.ts:12 | Session control command payload |
Key | Direction | Category | Producer | Description |
errorMessage | A→C | Public | acp-agent.ts:414,3066 | Readable error message that is parallel to stopReason: 'refusal' |
finishReason | A→C | Public | acp-view.ts:703 | Model finish reason |
outcome | A→C | Public | acp-agent.ts:3087-3088 | prompt result determination ( SUCCESS and others) |
businessFailed | A→C | Public | acp-utils.ts:1004 | Business failure flag for UI renderer to distinguish from transport failure |
cancelReason | A→C | Public | acp-protocol.ts:973 | Cancellation reason |
cancelCause | A→C | Public | automation-prompt-builder.ts:285 | Cancellation cause on the prompt result (read by automation first) |
terminationReason | A→C | Public | acp-broadcast-service.ts:435 | Termination reason (such as prompt_timeout) |
promptFailurePhase | A→C | Public | workbuddy-server/src/backend/prompt-replay-safety.ts:2 | Phase in which the prompt failure occurs |
promptFailureReason | A→C | Public | Same as above :3 | prompt failure reason |
promptReplaySafe | A→C | Public | Same as above :1 | Whether the failure can be safely replayed |
transportLost | A→C | Public | workbuddy-agent-adapter-next.ts:10689 | Transport connection loss flag |
transportError | A→C | Public | Same as above :10690 | Transport error code (such as ws_rpc_connection_lost) |
toolCallMeta in a centralized manner by the code block at acp-agent.ts:5013-5064.Key | Producer | Description |
toolName | acp-agent.ts:4093,4168 | Tool Name |
toolCallId | acp-broadcast-service.ts:287 | Associated Tool Call ID |
parentToolCallId | acp-agent.ts:3949,4004 | Parent tool call ID (subagent nesting) |
toolCancelReason | acp-agent.ts:578 | Tool cancellation reason ( permission_denied is used to distinguish it from normal cancellation) |
toolFailReason | acp-agent.ts:650 | Tool failure reason category |
toolResultTitle | persisted-transcript-projector.ts:72 | Tool result title (for transcript projection) |
description | acp-agent.ts:5047,6344 | Tool call description |
operation | acp-agent.ts:5046,6343 | Operation type (such as mcp-ui reverse tools/call) |
target | acp-agent.ts:5045,6342 | Operation target (such as MCP server name) |
filename | acp-utils.ts:654 | Associated file name |
images | acp-broadcast-service.ts:684 | Image payload |
rawResponse | acp-utils.ts:997 | Raw structured tool result, passed through to the UI renderer (such as web-search) |
bulkDeleteInfo | acp-agent.ts:5059-5060 | Batch deletion information |
bypassHint | acp-agent.ts:5056-5057 | Bypass hint |
interceptType | acp-agent.ts:5044,6758 | Interception type |
sandboxIntercept | acp-agent.ts:5013,5043 | Sandbox interception flag |
sandboxApprovalMode | acp-agent.ts:5053-5054 | Sandbox approval mode |
mcpUiIntercept | acp-agent.ts:4853,6341 | MCP-UI reverse call interception flag |
hook | acp-utils.ts:770,session-manager.ts:766 | Hook structured blocking information |
details | acp-agent.ts:6800 | Event supplementary details |
Key | Producer | Description |
decision | acp-broadcast-service.ts:289 | Permission decision result |
permissionResolved | acp-broadcast-service.ts:286 | Permission resolved notification |
planContent | api-schema.ts:1808 | Plan body of ExitPlanMode |
goalProgress | use-acp.ts:491-492 | Goal progress |
goalRecap | acp-broadcast-service.ts:487 | Goal recap |
goalStatus | use-acp.ts:522-523 | Target status |
interruptionRequest | acp-broadcast-service.ts:221,session-replay.ts:692 | Interruption (HITL) request payload |
promptSuggestion | prompt-suggestion-service.ts:502 | Prompt suggestion |
Key | Direction | Category | Producer | Description |
historyReplay | A→C | Public | session-replay.ts:392 | History replay boundary marker ( start / end) |
historyReplayTotalItems | A→C | Public | session-replay.ts:393 | Total number of replay items (only at start) |
rendererHistoryReplay | A→C | Public | conversation-frame-classifier.ts:83,replay-event-classifier.ts:82 | Renderer replay marker |
ownerSnapshotHistoryReplay | A→C | Private | replay-event-classifier.ts:87,conversation-frame-classifier.ts:84 | owner snapshot replay marker. The owner concept is only valid in session-payload multi-tenant scenarios. |
isSessionSeparator | A→C | Public | conversation-frame-classifier.ts:91 | Session separator frame marker |
separatorExtra | A→C | Public | Same as above :94 | Additional information of separator frame |
createTime | A→C | Public | Same as above :93 | Frame creation time |
offset | A→C | Public | workbuddy-agent-adapter-next.ts:6458 | Transcription source offset (legacy key) |
sourceOffset | A→C | Public | agent-member-utils.ts:242,team-runtime.ts:461 | Transcription source offset (new key, takes precedence over offset) |
originalBytes | A→C | Public | persisted-transcript-projector.ts:71 | Original number of bytes before transcription truncation |
session_info_update._meta.Key | Producer | Description |
compactType | context-protocol.ts:231 | Compression type, based on which the desktop adapter determines presentation. |
compactStatus | conversation-frame-classifier.ts:231 | Compression status |
compact-cancelled | context-protocol.ts:287 | { cancelled: true } — Compression canceled. |
compact-limit-reached | context-protocol.ts:295 | { limitReached: true } — Compression limit reached. |
compactTruncated | persisted-transcript-projector.ts:70 | The frame is truncated during compression. |
isCompactInternal | acp-agent.ts:3200,3396 | This prompt is triggered internally by compact (not counted as a user-visible turn). |
Key | Direction | Category | Producer | Description |
teamUpdate | A→C | Public | acp-team-bridge.ts:745,779 | Team status event (member status changes, and so on) |
memberEvent | A→C | Public | acp-team-bridge.ts:602 | Ownership tag of member streaming messages (member name) |
memberName | A→C | Public | acp-agent.ts:5037 | Member name to which the tool call belongs |
isTeamMember | A→C | Public | acp-agent.ts:5036 | The tool call comes from a team member. |
agentColor | A→C | Public | acp-agent.ts:5039 | Member display color |
syntheticTeammateMessage | A→C | Public | team-runtime-loader.ts:691,workbuddy-agent-adapter-next.ts:4945 | Synthetic teammate message (not directly output by the model) |
teammateSummary | A→C | Public | Same as above :693 / :4946 | teammate summary text |
src/node/workflow/acp/workflow-acp-bridge.ts:146-190, with the key space uniformly set to codebuddy.ai/workflow*.Key | Rows | Description |
workflowEventKind | :151 | Event type |
workflowRunId | :156,168 | Run ID |
workflowName | :157 | Workflow name |
workflowStatus | :158 | Running status |
workflowAgentCount | :159 | Total number of agents |
workflowCachedCount | :160 | Number of agents that hit the cache |
workflowPhaseCount | :161 | Total number of stages |
workflowError | :163 | Run-level error |
workflowPhase | :169 | Current stage |
workflowAgentKey | :175 | agent key |
workflowAgentLabel | :177 | agent display name |
workflowAgentPhase | :180 | agent phase |
workflowAgentError | :183 | agent-level error |
workflowAgentTokens | :186 | agent token consumption |
acp-utils.ts:481-491 and consumed by the Web UI at use-acp.ts:202-213. They carry source information from external channels such as WeCom.Key | Description |
channelSource | Channel source identifier |
channelSender | Sender ID |
channelSenderName | Sender display name |
channelChatId | Conversation ID |
channelChatType | Conversation type ( single / group) |
commandKind | Command type ( slash) |
Key | Direction | Category | Producer | Description |
sendMessageMode | C→A | Public | MCP-UI widget( mcp-app-handlers.ts:79,112) | Behavior routing for widget message write-back: send / fill |
message_queue_update | A→C | Public | acp-broadcast-service.ts:462 | Incremental message queue update |
newSessionId | A→C | Public | acp-command-attachment-router.ts:73 | New sessionId after a command triggers session creation |
sessionReset | A→C | Public | acp-command-attachment-router.ts:72 | Session reset (for example, /clear) |
Key | Direction | Category | Producer | Description |
usageByCategory | A→C | Public | acp-protocol.ts:64,1331 | Categorized usage of usage_update; invariant: sum(usageByCategory) === update.used |
contentFilterNotice | A→C | Public | context-protocol.ts:258 | Content filtering notice (when true, this text block is a filtering notification) |
hiddenPromptContext | C→A | Public | colleague-mention-context.ts:15 | This prompt block is hidden context and is not displayed in the UI. |
progress | A→C | Public | acp-agent.ts:3820,stream-json-protocol.ts:554 | Progress payload on session_info_update |
sourceEvent | A→C | Public | acp-utils.ts:146 | Objective description of the source event of this update (facets), for adapter routing |
acp-agent.ts:3437-3447.Key | Description |
requestModelId | Model ID used by the request |
requestModelName | Model name used by the request |
responseModelId | Actual response model ID |
responseModelName | Actual response model name ( conversation-event-machine.ts:334) |
completionDispatchId / completionExecutionDigest have been.buildEphemeralMetadata is also physically deleted, and its semantics are merged into §3.1.completionDispatchGrantV1 (structured per-dispatch execution authorization).Key | Direction | Category | Producer | Description |
status | A→C | Public | acp-session-info-router.ts:136-137,conversation-event-machine.ts:763 | Status field of session_info_update |
model | A→C | Public | stream-span-manager.ts:145 | Flat model name (for span attribution) |
sessionAdmissionV2, sessionGrantV1, completionDispatchGrantV1,authSession,productConfig,runtimeTransportCredential,runtimeSessionBindingV2,runtimeBindingToken,runtimeAuthority,ownerSnapshotHistoryReplayaccessToken, which has no producer but belongs to the credential plane, a total of 11 items never appear on the standard ACP plane._codebuddy.ai/* Extension Methods / Complete Notification List (44 Items)_meta keys, but they share the same namespace.packages/agent-client-protocol/src/common/types.ts:25-35.Method Name | Direction | Category | Description |
_codebuddy.ai/question | A→C(request) | Public | HITL question, waiting for client response ( acp-protocol.ts:900) |
_codebuddy.ai/resolveInterruption | C→A(request) | Public | The client responds to the interruption request ( acp-agent.ts:5565-5570). |
_codebuddy.ai/artifact | A→C(notify) | Public | Artifact push ( session-replay.ts:523) |
_codebuddy.ai/command | A→C(notify) | Public | Command event ( types.ts:25) |
_codebuddy.ai/checkpoint | A→C(notify) | Public | checkpoint event ( session-replay.ts:601) |
_codebuddy.ai/session/rollback | C→A(request) | Public | Session rollback ( acp-agent.ts:5812) |
_codebuddy.ai/session/rollbackFiles | C→A(request) | Public | File-level rollback |
_codebuddy.ai/session/previewFileRollback | C→A(request) | Public | Rollback preview |
_codebuddy.ai/file_history_snapshot | A→C(notify) | Public | File history snapshot ( types.ts:29) |
_codebuddy.ai/fileTreeChanged | A→C(notify) | Public | File tree change (filePath required) |
_codebuddy.ai/authUrl | A→C(notify) | Public | Login redirect URL ( types.ts:27) |
_codebuddy.ai/getUserInfo | C→A(request) | Public | Fetch user information ( acp-agent.ts:5578) |
_codebuddy.ai/uiControl | A→C(request) | Public | UI control command ( types.ts:35) |
_codebuddy.ai/system_init | A→C(notify) | Public | System initialization notification |
_codebuddy.ai/tool_input | A→C(request) | Public | Tool input query ( agent-provider/examples/question-example.ts:16) |
_codebuddy.ai/delegateTool | A→C(request) | Public | Tool proxy execution ( delegate-tool-manager.ts:299) |
_codebuddy.ai/delegateToolsChanged | C→A(notify) | Public | Change of the client-delegatable tool set ( acp-agent.ts:5580) |
_codebuddy.ai/refreshPlugins | C→A(request) | Public | Request plugin refresh ( acp-agent.ts:5584) |
_codebuddy.ai/plugins_changed | A→C(notify) | Public | Plugin set change |
_codebuddy.ai/mcp_servers_changed | A→C(notify) | Public | MCP server set change |
_codebuddy.ai/models_changed | A→C(notify) | Public | Model list change |
_codebuddy.ai/product_config_changed | A→C(notify) | Public | Product configuration change |
_codebuddy.ai/identity_changed | A→C(notify) | Public | Identity change broadcast (written by the main process and then broadcast to all live sessions) |
_codebuddy.ai/queue_state_changed | A→C(notify) | Public | Queue state change |
_codebuddy.ai/message_queue_snapshot_changed | A→C(notify) | Public | Message queue snapshot change |
_codebuddy.ai/automation_snapshot | A→C(notify) | Public | automation snapshot |
_codebuddy.ai/interaction_timeout | A→C(notify) | Public | Interaction timeout ( cloud-agent-event-bridge.ts:10) |
_codebuddy.ai/teams | A→C(notify) | Public | Team SSE event ( use-collab-queue.ts:5) |
_codebuddy.ai/conversation | A→C(notify) | Public | Conversation event ( use-conversation-events.ts:50) |
_codebuddy.ai/mcpUiCallTool | C→A(request) | Public | MCP-UI reverse tools/call |
_codebuddy.ai/mcpUiReadResource | C→A(request) | Public | MCP-UI read resource |
_codebuddy.ai/mcpUiUpdateModelContext | C→A(request) | Public | MCP-UI update model context |
_codebuddy.ai/mcpUiRequestDisplayMode | C→A(request) | Public | MCP-UI request display mode |
_codebuddy.ai/mcpUiResourceTeardown | C→A(request) | Public | MCP-UI resource teardown |
_codebuddy.ai/respondToSandboxIntercept | C→A(request) | Public | Respond to sandbox interception ( codebuddy-code-backend.ts:1909) |
_codebuddy.ai/admitControl | C→A(request) | Private | Controls Session admission. The process-login composition root directly throws (process-login-acp-admission-service.ts:87-90), and it is used only by workbuddy-host-sidecar. |
_codebuddy.ai/runtimeCredentialUpdate | C→A(request) | Private | per-session exact credential update ( acp-agent.ts:5595) |
_codebuddy.ai/runtimeControlCredentialUpdate | C→A(request) | Private | control binding credential update ( acp-agent.ts:5597) |
_codebuddy.ai/runtimeOwnerCredentialUpdate | C→A(request) | Private | Owner-level batch credential update ( acp-agent.ts:5599), corresponding to bulkApplyExactCredentialUpdates |
_codebuddy.ai/activateWorkbuddyOwnerRuntime | C→A(request) | Private | New in C3: injects an owner authorization (authSession + product material + credential handle) into the workbuddy-single process once, after which session/new has zero identity meta. Payload = {proof, processInstanceId, handshakeNonce, runtimeConfigSha256, ownerGeneration}, verification point: workbuddy-admission-security.ts activateOwnerRuntime |
_codebuddy.ai/activateCompletionRuntime | C→A(request) | Private | Activates the completion warm runtime. **Starting from C3, claims append credentialMaterial**, and it also handles process-level owner injection on the warm side. After credential refresh, it is called again with the same ownerGeneration and a new proof, using full replacement semantics. |
_codebuddy.ai/completionDispatch | C→A(request) | Private | Dispatch a completion ( acp-agent.ts:5738). |
_codebuddy.ai/completionRuntimeDiagnostics | C→A(request) | Private | completion runtime diagnostics ( acp-agent.ts:5708) |
_codebuddy.ai/disposeEphemeralSession | C→A(request) | Private | Terminate ephemeral session ( acp-agent.ts:5676). |
_codebuddy.ai/disposePersistentSession | C→A(request) | Private | Terminate persistent session ( acp-agent.ts:5705). |
_codebuddy.ai/example | — | — | Placeholder method name for testing, appears only in workbuddy-server/src/server-owned-handlers.spec.ts:2113, with no production implementation. |
session/rollbackFiles / session/previewFileRollback (they share the token codebuddy.ai/session with session/rollback, so grep counts it only once).token | Occurrence Form | Description |
codebuddy.ai/ | startsWith('codebuddy.ai/') / startsWith('_codebuddy.ai/') | Namespace prefix itself. Guard points: workflow-acp-bridge.spec.ts:82, sandbox-proxy/src/handler/artifacts-proxy.ts:70, sandbox-proxy/src/replay/replay.ts:1047 |
codebuddy.ai/workflow | codebuddy.ai/workflow* in comments | Key space wildcard notation ( workflow-acp-bridge.ts:146), not a standalone key. |
codebuddy.ai/mcpUi | _codebuddy.ai/mcpUi* in comments | Wildcard notation for five MCP-UI extension methods ( mcp-apps-extmethod.spec.ts:4) |
https://www.codebuddy.ai/... / https://code.codebuddy.ai/... and are protocol-independent:token | Source |
codebuddy.ai/docs | keybinding-template.ts:18,52,mcp-approval-box.tsx:16 |
codebuddy.ai/schemas | keybinding-template.ts:17,51 |
codebuddy.ai/login | chat-ui/src/browser/login/login.tsx:149 |
codebuddy.ai/agents | agent-ui/src/utils/workbuddy-share-origin.spec.ts:312 |
codebuddy.ai/profile | use-error-banner.tsx:186(.../profile/plan) |
codebuddy.ai/v2 | model-provider.spec.ts:454,520(API baseURL) |
codebuddy.ai/* _meta keys for identity or admission purposes. Keys marked as "private" in §3.1 are issued by the CodeBuddy internal composition root, and any client-generated ones will be rejected (they will fail envelope validation, digest comparison, and fencing).session/prompt (requestId / messageId / messageRequestId / userMessageId / promptRequestId / clientRequestId / sendTime / traceparent) are the only set that clients are recommended to produce proactively — they only affect instrumentation and trace linking, and do not participate in any authentication decisions._codebuddy.ai/* extension methods: the 9 marked as "private" in §4 (admitControl + three runtime*CredentialUpdate--acp startup method, Zed configuration, and protocol features_meta resident e2e: src/e2e/acp-zero-meta-contract.spec.tssrc/node/session/runtime-admission-acp-adapter.ts, src/node/session/process-login-acp-admission-service.ts, src/node/session/multi-owner-acp-admission-service.tspackages/runtime-admission-protocol/src/runtime-admission-contract.tsWas this page helpful?
You can also Contact sales or Submit a Ticket for help.
Help us improve! Rate your documentation experience in 5 mins.
Feedback