Manifest reference
act-build pack writes the act:component WASM custom section (CBOR-encoded). Its contents are merged from several sources:
- Base —
name,version,descriptionfrom the language manifest (Cargo.toml,pyproject.toml, orpackage.json) - Inline patch — the ACT table inside that same manifest:
[package.metadata.act](Rust),[tool.act](Python), or"act"(JS/TS) act.toml— sidecar patch, applied last and therefore highest priorityact-build pack --set <key>=<value>— a final per-invocation override
Later sources override earlier ones (RFC 7396 merge-patch). Note that the SDK macros contribute
tool definitions at compile time, not component metadata: pack resolves the manifest from
these files and writes the act:component section from them.
Basic fields
Section titled “Basic fields”Keys live under [std]. Name, version, and description come from the language manifest by default.
[package]name = "component-sqlite"version = "0.2.3"description = "SQLite database"
[package.metadata.act]# optional overrides/additions[project]name = "python-eval"version = "0.1.1"description = "Python interpreter"
[tool.act.std]# optional overrides/additions[std]name = "sqlite" # last-wins override of the Cargo / pyproject nameversion = "0.2.3"description = "SQLite database"Capability declarations
Section titled “Capability declarations”A component declares the WASI capabilities it needs. The host uses this as a ceiling on what the user’s policy can grant: an undeclared capability, or a declaration with an empty allow list, is a hard deny regardless of what the operator grants.
Filesystem
Section titled “Filesystem”[std.capabilities."wasi:filesystem"]description = "Stores the database file."
[[std.capabilities."wasi:filesystem".allow]]path = "**" # glob; "**" means any pathmode = "rw" # "ro" or "rw"Multiple [[...allow]] entries are OR’d. The user’s runtime policy is intersected with this ceiling.
[std.capabilities."wasi:http"]description = "Fetches OpenAPI specs from public catalogs."
[[std.capabilities."wasi:http".allow]]host = "petstore3.swagger.io" # "*" = any host; "*.example.com" = suffixscheme = "https" # optional — any scheme if absentmethods = ["GET"] # optional — any method if absentports = [443] # optional — standard port for the schemeSockets
Section titled “Sockets”[std.capabilities."wasi:sockets"]description = "Connects to the configured Postgres server."
[[std.capabilities."wasi:sockets".allow]]host = "*"ports = [5432] # requiredprotocols = ["tcp"]Filesystem topology
Section titled “Filesystem topology”Beyond authorization, a filesystem declaration can bind a host directory to a stable guest path,
so the component’s code opens a fixed path regardless of who runs it. Authorization still comes
from the allow entries — keep the host paths in sync:
[[std.capabilities."wasi:filesystem".params.mounts]]type = "bind"guest = "/data"host = "~/.my-component"Credentials
Section titled “Credentials”A component can declare the credentials it expects, which is what act login prompts for:
# Bare table — the class carries no constraints, but an undeclared class is# denied outright, so this line is required to reach the credential store.[std.capabilities."act:credentials"]
[[std.credentials]]key = "default" # the key a session uses when its args name nonedescription = "iikoServer API user"
[[std.credentials.fields]]key = "iiko-server:login"label = "iikoServer login"
[[std.credentials.fields]]key = "iiko-server:password"label = "iikoServer password"act-build pack refuses a manifest that declares [[std.credentials]] without the
act:credentials capability.
Agent skill embedding
Section titled “Agent skill embedding”If a skill/ directory exists at the package root, act-build pack tars it and embeds it as the act:skill custom section. Extract with act skill <component.wasm> -o out/. See Agent Skills.
Validation
Section titled “Validation”act-build validate path/to/component.wasmChecks that declared capabilities parse, that the CBOR section is readable, and that the file is a valid component.
Merge order cheatsheet
Section titled “Merge order cheatsheet”┌───────────────────────────────┐│ Cargo / pyproject / package │ name, version, description└───────────────────────────────┘ ▼┌───────────────────────────────┐│ [package.metadata.act] │ inline ACT table in that same manifest│ [tool.act] / "act" │└───────────────────────────────┘ ▼┌───────────────────────────────┐│ act.toml (sidecar) │ the conventional home for capabilities└───────────────────────────────┘ ▼┌───────────────────────────────┐│ act-build pack --set k=v │ per-invocation override (strings only)└───────────────────────────────┘ ▼ act:component (CBOR)