Source: schemas/library_manifest.schema.json

Generated automatically from the published contract sources.

Source path: schemas/library_manifest.schema.json.

Schema fields

JSON pointer Description and constraints
"" (root) The shape of `manifest.json` at the root of a project's library folder (LC-07 in the library catalog contract; SPM-L0-50's `system/` row). It is the record of what one project holds — not a copy of the catalog, which is what a publish offers. The two share `name`, `version` and the closure hash on purpose, so the comparison `list_library` makes against a held set compares like with like. Only the turnzero-cloud command's `library take`, which the served installation and update skills direct, writes the manifest (PLD-L0-100). The registrar's `validate` MCP tool with library kind checks manifest form, listed-entry hashes, and unnamed entry folders. Coordinated file and hash edits can pass this local check; it does not authenticate version, source-commit, or fetch-time claims against a publication. Use `list_library` for the publication-currency comparison under LC-06. A test in the platform's suite holds this shape.

$schema: https://json\-schema\.org/draft/2020\-12/schema
version: 2026-10-03.1
title: Turn Zero Cloud — a project's library folder manifest
Type: object
Additional properties: false
Required fields: ["manifest_version","entries"]
/properties/manifest_version The format's revision. An unknown revision is refused as malformed rather than read best-effort, on MAN-01's rule for the admission manifest — a reader that guesses at a format it does not know is a reader that silently drops what it did not understand.

Required value: 1
/properties/entries One row per library entry the project holds. Holding none is the empty array rather than an absent member, so a folder that exists and holds nothing is distinguishable from one whose manifest was never written.

Type: array
uniqueItems: true
/properties/entries/items Type: object
Additional properties: false
Required fields: ["name","version","closure_hash","source_commit","fetched_at"]
/properties/entries/items/properties/name The entry's stable name, as the catalog answers it: a package's folder name, `ui/<vocabulary>`, `fonts/<family>`, or `library/prd` for the library's own requirements entry.

Type: string
Minimum length: 1
/properties/entries/items/properties/version The version held, on FTR-L0-62's front-matter spelling. Null on a font family, which carries no specification of its own and so no version of its own, and on the library's own requirements entry, whose two documents declare none — the closure hash is what a consumer compares for those.

Type: ["string","null"]
/properties/entries/items/properties/closure_hash sha256 over the entry's whole closure, as the catalog computed it. This is what makes the folder checkable rather than merely present: `validate` rehashes each entry against this value and names any whose bytes have moved, detecting file changes against the locally recorded hash under SPM-L0-49. This checks local consistency; coordinated file and hash edits can pass.

Type: string
Pattern: ^[0-9a-f]{64}$
/properties/entries/items/properties/source_commit The library commit this entry was published from, so a holder can trace its bytes back to the source that produced them without the server's help.

Type: string
Minimum length: 7
/properties/entries/items/properties/fetched_at When this entry was written into the folder, ISO 8601 in UTC. The publish's own date is the catalog's; this is the consumer's, and the two differ whenever a project takes a version some time after it was published. Spelled as a pattern rather than JSON Schema's `date-time` format, because the format vocabulary is an optional ajv package this project does not ship and an unrecognized format is silently ignored under strict mode — a check that passes anything.

Type: string
Pattern: ^[0-9]{4}-[0-9]{2}-[0-9]{2}T[0-9]{2}:[0-9]{2}:[0-9]{2}(\.[0-9]+)?Z$

Complete source

{
  "$schema": "https://json-schema.org/draft/2020-12/schema",
  "version": "2026-10-03.1",
  "title": "Turn Zero Cloud — a project's library folder manifest",
  "description": "The shape of `manifest.json` at the root of a project's library folder (LC-07 in the library catalog contract; SPM-L0-50's `system/` row). It is the record of what one project holds — not a copy of the catalog, which is what a publish offers. The two share `name`, `version` and the closure hash on purpose, so the comparison `list_library` makes against a held set compares like with like. Only the turnzero-cloud command's `library take`, which the served installation and update skills direct, writes the manifest (PLD-L0-100). The registrar's `validate` MCP tool with library kind checks manifest form, listed-entry hashes, and unnamed entry folders. Coordinated file and hash edits can pass this local check; it does not authenticate version, source-commit, or fetch-time claims against a publication. Use `list_library` for the publication-currency comparison under LC-06. A test in the platform's suite holds this shape.",
  "type": "object",
  "additionalProperties": false,
  "required": ["manifest_version", "entries"],
  "properties": {
    "manifest_version": {
      "description": "The format's revision. An unknown revision is refused as malformed rather than read best-effort, on MAN-01's rule for the admission manifest — a reader that guesses at a format it does not know is a reader that silently drops what it did not understand.",
      "const": 1
    },
    "entries": {
      "description": "One row per library entry the project holds. Holding none is the empty array rather than an absent member, so a folder that exists and holds nothing is distinguishable from one whose manifest was never written.",
      "type": "array",
      "uniqueItems": true,
      "items": {
        "type": "object",
        "additionalProperties": false,
        "required": ["name", "version", "closure_hash", "source_commit", "fetched_at"],
        "properties": {
          "name": {
            "description": "The entry's stable name, as the catalog answers it: a package's folder name, `ui/<vocabulary>`, `fonts/<family>`, or `library/prd` for the library's own requirements entry.",
            "type": "string",
            "minLength": 1
          },
          "version": {
            "description": "The version held, on FTR-L0-62's front-matter spelling. Null on a font family, which carries no specification of its own and so no version of its own, and on the library's own requirements entry, whose two documents declare none — the closure hash is what a consumer compares for those.",
            "type": ["string", "null"]
          },
          "closure_hash": {
            "description": "sha256 over the entry's whole closure, as the catalog computed it. This is what makes the folder checkable rather than merely present: `validate` rehashes each entry against this value and names any whose bytes have moved, detecting file changes against the locally recorded hash under SPM-L0-49. This checks local consistency; coordinated file and hash edits can pass.",
            "type": "string",
            "pattern": "^[0-9a-f]{64}$"
          },
          "source_commit": {
            "description": "The library commit this entry was published from, so a holder can trace its bytes back to the source that produced them without the server's help.",
            "type": "string",
            "minLength": 7
          },
          "fetched_at": {
            "description": "When this entry was written into the folder, ISO 8601 in UTC. The publish's own date is the catalog's; this is the consumer's, and the two differ whenever a project takes a version some time after it was published. Spelled as a pattern rather than JSON Schema's `date-time` format, because the format vocabulary is an optional ajv package this project does not ship and an unrecognized format is silently ignored under strict mode — a check that passes anything.",
            "type": "string",
            "pattern": "^[0-9]{4}-[0-9]{2}-[0-9]{2}T[0-9]{2}:[0-9]{2}:[0-9]{2}(\\.[0-9]+)?Z$"
          }
        }
      }
    }
  }
}