Capability
A signed grant from a space owner to another key: a role (WRITER or AGENT), an optional path scope, and nothing that expires or revokes it.

Extends

type
Blob type tag, always `Capability`.
Capabilityoptional
signer
Public key of the account or device that signed the blob.
inherited
sig
Signature over the canonical DAG-CBOR of the blob with `sig` set to 64 zero bytes.
inherited
ts
When the signer says the blob was made, in Unix milliseconds; not checked against real time.
inherited
delegate
The key that receives the grant.
audience
Only on short-lived, unstored capabilities that prove account ownership to a peer or HTTP server; never on stored grants.
optional
path
Path the grant is scoped to, recursive by segment (`/team` covers `/team/notes`); empty for the whole space.
optional
role
What the delegate may do: `WRITER` publishes under `path`, `AGENT` acts as the issuer (path must be empty).
optional
label
Public, immutable note describing the grant, at most 512 bytes.
optional

A capability is the blob that lets someone other than the space owner write into a space. The owner signs it, names the key that receives the grant (the delegate), picks a role, and optionally limits it to a path. Every node checks Refs against the capabilities it has stored, so the whole network enforces the grant. Permissions has the full model, the exact authorization rule and a worked example.

The signer is both the issuer and the space. Only the space owner's key can sign a capability for that space, so a delegate cannot issue grants in it. Any delegate can still pass its authority one more hop by making another key its AGENT. role is WRITER (publish under the path and everything beneath it) or AGENT (act as the issuer; the path must be empty). path scopes by segment and is always recursive: a grant at /team covers /team/notes but not /teammates. label is a public, immutable note of at most 512 bytes. audience appears only on the short-lived, unstored capabilities that peers and HTTP clients sign to prove they hold an account. A stored grant never sets it.

There is no expiry and no revocation. A capability that names a Ref's signer gives the same result whether it arrives before that Ref or after it: the daemon stashes an unauthorized Ref and retries it when a capability naming its signer is indexed. A late grant one hop up an AGENT chain names a different key and does not trigger that retry. An AGENT delegate inherits the issuer's own space and the issuer's direct grants elsewhere for exactly one hop.

Create one with seed-cli capability create --delegate <uid> --role WRITER --path /team in the CLI, with createCapability in the SDK, from a document's Collaborators view in the Seed app, or with the agent write action capability.grant.

See also

    Permissions: the authorization rule and worked examples.

    role: what WRITER and AGENT allow.

    ref: the blob a capability authorizes.

    profile: aliases that need an AGENT capability.

    Identity: accounts, spaces and linked keys.

    blob: the signed envelope.

Do you like what you are reading? Subscribe to receive updates.

Unsubscribe anytime