std:* metadata keys
Metadata keys are namespaced strings. std: is reserved by the protocol and registered in
ACT-CONSTANTS, which is the
normative list; anything else belongs to whoever coined it (acme:priority, pg:sslcert).
Values are CBOR-encoded. Where a key appears matters — the same name can mean different things in two positions, and §7 and §8 of the registry contain a deliberate example of exactly that.
Component metadata
Section titled “Component metadata”Lives under [std] in the manifest, and ends up in the act:component custom section. See
Manifest reference.
| Key | Type | Purpose |
|---|---|---|
name | string | Component name. Required |
version | string | SemVer. Required |
description | string or localized map | Human-readable description |
default-language | string | BCP 47 tag, used when a localized-string::plain carries no language |
capabilities | map | Capability declarations, keyed by capability id |
Tool definition
Section titled “Tool definition”On tool-definition.metadata — what a component says about each of its tools.
| Key | Type | Purpose |
|---|---|---|
std:read-only | bool | Does not modify state. Drives MCP readOnlyHint |
std:idempotent | bool | Same arguments, same effect. Drives MCP idempotentHint |
std:destructive | bool | May irreversibly modify state. Drives MCP destructiveHint |
std:timeout-ms | uint | Suggested timeout; the host may override |
std:usage-hints | localized-string | When to use this tool, for an agent |
std:anti-usage-hints | localized-string | When not to use it |
std:examples | array of bstr | Example calls, as CBOR-encoded argument maps |
std:tags | array of string | Categorisation |
std:session-op | string | "open" / "close" — marks a tool synthesised by a transport adapter as a session lifecycle operation |
Reserved tool names
Section titled “Reserved tool names”open_session and close_session are synthesised by the MCP adapter for components exporting
session-provider, so a component must not define tools with those names. On a collision the host
suffixes its own (open_session__act) and warns.
Cross-cutting
Section titled “Cross-cutting”May appear on any metadata field — a tool call, a list-tools response, a content part, an
open-session.
| Key | Type | Purpose |
|---|---|---|
std:session-id | string | Session issued by session-provider. See Sessions |
std:traceparent | string | W3C Trace Context traceparent |
std:tracestate | string | W3C Trace Context tracestate |
std:request-id | string | Correlation id for logging |
std:progress-token | string | MCP-compatible progress token |
std:agent-id | string | Identifies the calling agent; informational, format implementation-defined |
Transport adapters propagate std:traceparent and std:tracestate to and from the corresponding
HTTP headers or MCP request extensions.
std:on-behalf-of is reserved for future use — usable with application-defined semantics, but
not yet something to rely on across implementations.
Content parts
Section titled “Content parts”On content-part.metadata, for reporting progress from inside a streaming result.
| Key | Type | Purpose |
|---|---|---|
std:progress | uint | Units completed so far |
std:progress-total | uint | Total units, if known |
Authentication
Section titled “Authentication”Keys a component accepts in open-session.args — not in per-call metadata, which is
discouraged for new designs because a credential repeated per call is a credential in the agent’s
context per call. See Credentials.
| Key | Type | Purpose |
|---|---|---|
std:api-key | string | API key for the external service |
std:bearer-token | string | OAuth2/OIDC access token, or a generic bearer token |
std:username | string | Basic auth |
std:password | string | Basic auth |
Bridges
Section titled “Bridges”| Key | Type | Purpose |
|---|---|---|
std:forward | object | Opaque metadata blob passed to the next component in a chain; each bridge level unwraps one layer |
Error kinds
Section titled “Error kinds”On error.kind. See Troubleshooting for what to do about each.
| Kind | Meaning |
|---|---|
std:not-found | The named tool does not exist |
std:invalid-args | Arguments or metadata failed schema validation |
std:timeout | Exceeded the declared or host-configured timeout |
std:capability-denied | The component used a capability that was not granted |
std:session-not-found | A call referenced a session id the component does not recognise |
std:credential-required | A credential the component needs is absent from its profile. The host surfaces it with a command the user can run to provision it — neither the error nor the command describes the material |
std:internal | An unrecoverable error inside the component |
Capability identifiers
Section titled “Capability identifiers”Keys of the std.capabilities map. See Policy & sandbox for the constraint
shapes each one accepts.
| Id | Parameters | Purpose |
|---|---|---|
wasi:http | — | Outbound HTTP |
wasi:filesystem | mount-root, mounts | Filesystem access, plus the guest-path topology |
wasi:sockets | — | Outbound TCP and UDP |
act:credentials | — | The host credential store. A bare table; undeclared means denied |
Third-party capabilities use their own namespace (acme:gpu/compute).
Semantic classes
Section titled “Semantic classes”The ids above name resources the host mediates by interception. A semantic class names an
action the host cannot see, because it travels over a channel the operator already permitted —
db:drop, browser:navigate. They are declared like any other class and surfaced through
act:consent.
They are component-defined: there is no registry of well-known ones, and none is reserved. Two components in different domains may pick the same identifier and neither is authoritative. Three rules hold regardless:
- A class absent from the declaration is denied, and no grant widens it.
- A declaration must name a concrete class.
"db:*"is not a valid declaration — a reader could not tell what the artifact can ask for. - A class should separate irreversible actions from routine ones —
db:dropapart fromdb:ddl— so the destructive case can be refused without refusing the rest.
[std.capabilities."db:drop"]description = "Destructive operations (DROP, TRUNCATE)."
[[std.capabilities."db:drop".allow]]key = "test_*"ACT-CONSTANTS is normative and gets new keys first; this page is an index onto it.