Capability
A signed grant from a space owner to another key: a role (WRITER or AGENT), an optional path scope, and nothing that expires or revokes it.
name
Capability
summary
A signed grant from a space owner to another key: a role (WRITER or AGENT), an optional path scope, and nothing that expires or revokes it.
Schema definitionThe schema this document defines, for other documents to use.

Extends — a signed blob: the envelope (signer, sig, ts) is inherited

type
Blob type tag, always `Capability`.
Capabilityoptional
delegate
The key that receives the grant.
audience
Only on short-lived, unstored capabilities that prove account ownership to a peer or HTTP server; never on stored grants.
optional
path
Path the grant is scoped to, recursive by segment (`/team` covers `/team/notes`); empty for the whole space.
optional
role
What the delegate may do: `WRITER` publishes under `path`, `AGENT` acts as the issuer (path must be empty).
optional
label
Public, immutable note describing the grant, at most 512 bytes.
optional