* pwa: read vault values in the browser with a pasted identity key The web app listed vaults but could never show a value: decryption needs the member's X25519 secret key, which only lives in identity.json on the machine that ran `logicsrc login`. Each vault now has a page (/teams/:slug/vaults/:id, linked from the dashboard) listing its secret names. Paste the identity key (or the whole identity.json) and public/vault.js decrypts in the browser with the same libsodium calls as the CLI: crypto_box_seal_open for the grant, then crypto_secretbox_open_easy per value. Nothing is sent to the server. - The pasted key is checked against the public key the server has on file before use, so a key from another machine is named, not a generic failure. - Show / Copy per value, Download .env, Forget key. The key is kept in sessionStorage unless "remember on this device" is ticked. - A member with no identity yet can create one in the browser. That registers only the public half, and is offered only when no key is registered, since replacing one would orphan every grant sealed to it. - libsodium is served from node_modules at /vendor (no CDN), like simplewebauthn. - Vault pages are no-store and the service worker no longer caches no-store pages. - CLI: `logicsrc teams key` prints the secret key to stdout alone (pipe to pbcopy) and warns when the server holds a different public key. The page also gives a jq one-liner for CLIs released before this command. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * pwa: rename data-secret to data-key-name ThreatCrush read data-secret="…" as a hardcoded credential (2 high, both the attribute name, never a value). Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * CLI 0.5.0 for teams key; install via install.sh, not npm @logicsrc/cli is not on npm; the CLI ships through curl -fsSL https://logicsrc.com/install.sh | sh, which builds master and reports the version from packages/cli/package.json. 0.5.0 marks the first build with teams key, and the vault page now says so and points older installs at the jq fallback. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com> |
||
|---|---|---|
| .github | ||
| .nixpacks | ||
| apps | ||
| docs | ||
| examples | ||
| packages | ||
| plugins | ||
| prd | ||
| scripts | ||
| supabase | ||
| .dockerignore | ||
| .env.example | ||
| .gitignore | ||
| bun.lock | ||
| LICENSE | ||
| package.json | ||
| README.md | ||
| tsconfig.base.json | ||
LogicSRC
LogicSRC is an open standards initiative for human and AI agent coordination, maintained by Profullstack, Inc.
CommandBoard.run is the first hosted product built on LogicSRC: a modern BBS where humans and AI agents coordinate work through boards, tasks, DID identity, OAuth, CLI, TUI, plugins, reputation, audit logs, and payments.
The standards surface is named logicsrc. External tools can consume LogicSRC contracts, but the LogicSRC CLI remains the OpenStandards command surface.
Monorepo
apps/
commandboard-api REST API reference service
commandboard-web PWA shell
packages/
cli logicsrc OpenSpec CLI
opencontext OpenContext reference implementation (resolver, scopes, bundles, adapters)
openontology OpenOntology reference engine (entities, claims, queries, change sets)
openprd OpenPRD reference implementation (numbered PRDs, lifecycle, task bridge)
openfleet OpenFleet reference implementation (record, ledger, sysop verbs, Claude Code hooks)
logicsrc-mcp @profullstack/logicsrc-mcp standards MCP server
sdk SDK contract types and helpers
tui terminal UI
schemas LogicSRC JSON schemas
validators schema validation utilities
agentad AgentAd Marketplace exchange (auction, metering, settlement)
plugin-core plugin manifest and loader runtime
plugins/
coinpay default DID, wallet, payment, and escrow plugin
ugig default jobs and gigs marketplace plugin
c0mpute work-in-progress compute jobs and worker pools plugin
docs/
specs, CLI conventions, permissions, and roadmap notes
examples/
openontology/ethereum-ecosystem fictional ecosystem map demonstrating OpenOntology
opencontext/* five OpenContext repositories, from minimal to multi-agent
prd/
numbered OpenPRD proposals
scripts/
install.sh curl | sh installer
Quick Start
bun install
bun run check
npm --workspace @logicsrc/cli run dev -- --openspec agentswarm --yolo --repo profullstack/logicsrc
npm --workspace @logicsrc/cli run dev -- openspec import
npm --workspace @logicsrc/cli run dev -- openspec export --out logicsrc-openspec-summary.md
npm --workspace @logicsrc/cli run dev -- --openspec-only task validate packages/schemas/fixtures/task.yaml
npm --workspace @logicsrc/cli run dev -- agentswarm --yolo --repo profullstack/logicsrc
npm --workspace @logicsrc/cli run dev -- plugins
npm --workspace @logicsrc/cli run dev -- tui
npm --workspace @profullstack/logicsrc-mcp run build
node packages/logicsrc-mcp/dist/index.js
OpenWall proposal
OpenWall proposes broadcasts to explicitly selected connections, followers,
following, or service users, plus direct messages through verified contact routes. The draft
defines recipient consent, private delivery outcomes, and a public/private AT Protocol mapping.
Message and receipt JSON Schemas and fixtures are included; delivery services and the proposed
logicsrc wall commands are not implemented.
OpenPRD
OpenPRD is a lightweight standard for product requirements documents: a repo
keeps a numbered, committed collection under prd/, one Markdown file each, with front-matter, a
fixed set of eight sections, and a lifecycle. @logicsrc/openprd implements it.
npm --workspace @logicsrc/cli run dev -- prd new "Expand the parked-domain service"
npm --workspace @logicsrc/cli run dev -- prd validate ./prd --strict
npm --workspace @logicsrc/cli run dev -- prd status 0001 Review
npm --workspace @logicsrc/cli run dev -- prd tasks 0001 --priority P0
Conformance failures (filename, front-matter, id match, the eight sections in order) are errors;
lint findings are warnings that --strict promotes. The lifecycle is enforced — Draft cannot
jump to Final, and Superseded must name its replacement. prd tasks is the optional bridge:
each R# becomes one schema-valid logicsrc.task.
OpenOntology
LogicSRC OpenOntology is an open contract for durable, source-backed domain knowledge shared by humans and AI agents: typed entities, claims that carry provenance and time, a portable query AST, and governed change sets. It is storage-agnostic, model-provider-neutral, and works offline with no account.
npm --workspace @logicsrc/cli run dev -- ontology init my-ecosystem
npm --workspace @logicsrc/cli run dev -- ontology validate my-ecosystem --strict
npm --workspace @logicsrc/cli run dev -- ontology query run contributors --dir my-ecosystem
✓ 3 entity types
✓ 4 relationship types
✓ 8 entities
✓ 14 claims
✓ 2 sources
OpenOntology package is valid.
Claims are append-only and agents propose rather than apply: a corrected fact becomes a dispute, retraction, or supersession, and every answer traces back to the claims, evidence, and sources behind it.
Surfaces: a SQLite/Turso storage adapter, a REST + SSE reference service described by OpenAPI at
/api/ontologies/openapi, MCP resources and tools, JSON-LD/RDF/SHACL export, seven source adapters
that propose rather than apply, keyboard-first TUI panels, and a read-only web explorer at
/openontology/explore. See also
governance and
interoperability.
OpenContext
LogicSRC OpenContext is an open specification for durable, portable, permissioned, provenance-aware context shared between humans and AI agents. It defines how organizational knowledge is described, authorized, versioned, resolved, audited, and handed between replaceable workers without losing institutional state.
An agent should be replaceable without losing organizational knowledge.
npx @logicsrc/opencontext init my-context
npx @logicsrc/opencontext validate --strict
npx @logicsrc/opencontext resolve --role support --task "customer asked for a refund" --explain
Included:
✓ mission canonical
✓ policies.refunds canonical
✓ procedures.refund approved
Excluded:
- decisions.2026-08-09-adopt-opencontext not-in-scope (no include pattern matches)
Digest: sha256:81b41a915ee68f744e91ef0d7760440de51b603088de1a6f21ea6f337bb374a8
Authorization runs before relevance, so an agent never ranks context it may not read; authority is declared rather than inferred from retrieval rank; unresolved canonical conflicts are reported rather than quietly settled; and resolution is deterministic, so a decision can cite the exact bundle digest it was made from. Untrusted content — tickets, chats, scraped pages — keeps its trust level through resolution and is fenced and labelled in rendered bundles.
It is not a memory database. Memory is one possible context source; OpenContext is the control plane above systems that remain the sources of truth. It runs from a folder and a Git repository with no account, no server, and no telemetry.
Also available as logicsrc context <command>, sharing one implementation with the standalone
binary. See the specification, CLI,
SDK, security model, and
conformance guide.
One command for every LogicSRC tool
logicsrc is the umbrella: every LogicSRC standard that has a CLI is a word after it, and the word runs the same code as the standalone command, so the two cannot drift.
logicsrc vault … # OpenCreds (also `opencreds`)
logicsrc prd … # OpenPRD
logicsrc ontology … # OpenOntology
logicsrc context … # OpenContext (also `opencontext`)
logicsrc fleet … # OpenFleet: open, cap, tree, stop, log, hooks install
logicsrc openmcp … # OpenMCP: relays, find, call, add, probe, serve (also `openmcp`)
logicsrc openspec … # import, export, change; any other word is OpenSpec.dev's own CLI (init, list, validate, archive, show)
logicsrc mcp # the LogicSRC MCP server over stdio (also `logicsrc-mcp`)
openmcp is the one that lives in its own repository (logicsrc/openmcp); it is a dependency here and its main is called with your arguments untouched. It needs Node 24 (node:sqlite); on an older Node that one word says so and the rest of the CLI keeps working. The standalone install, which brings its own Node 24, is curl -fsSL https://openmcp.logicsrc.com/install.sh | sh.
MCP
LogicSRC exposes a standards-focused MCP server as @profullstack/logicsrc-mcp, and logicsrc mcp runs it.
It provides read-only resources for docs and schemas, validation/example tools, and prompt templates for creating LogicSRC-compatible documents.
v1.0.0 Priorities
- LogicSRC task, agent, run, event, permission, and plugin schemas.
- AgentAd: disclosed, agent-readable ad schemas for CLI/agent advertising (see
docs/agentad.md); cl1s.tech is the reference network. The two-sided exchange on top is specified indocs/agentad-marketplace.md. - LogicSRC CLI, SDK, TUI, PWA, MCP, and curl-compatible API conventions.
- CommandBoard.run reference implementation.
- Monorepo-maintained plugin system.
- Credential Sharing OpenSpec for end-to-end-encrypted team vaults, .env, Doppler, Railway variables, GitHub Secrets, sh1pt, and
~/.sshkeys. - CoinPay as the default payment, DID, wallet, and escrow plugin.
- uGig as the default jobs and gigs marketplace plugin.
- c0mpute as a work-in-progress compute jobs and worker pools plugin.
- Installer, update/upgrade, remove/uninstall workflows.
OpenABTest draft
OpenABTest defines reusable experiment manifests and private eligibility, assignment, exposure, conversion and accounting events. The Chovy example compares 5%, 10% and 20% discounts on every referred purchase, with sticky customer assignment and affiliate payout withheld until actual costs and fees are reconciled. Schemas, validators and SDK constructors ship in 0.3.0; assignment, analytics and payment runtimes remain the integrating service's job.