Skip to content

std:* metadata keys

Metadata keys are namespaced strings. std: is reserved by the protocol and registered in ACT-CONSTANTS, which is the normative list; anything else belongs to whoever coined it (acme:priority, pg:sslcert).

Values are CBOR-encoded. Where a key appears matters — the same name can mean different things in two positions, and §7 and §8 of the registry contain a deliberate example of exactly that.

Lives under [std] in the manifest, and ends up in the act:component custom section. See Manifest reference.

KeyTypePurpose
namestringComponent name. Required
versionstringSemVer. Required
descriptionstring or localized mapHuman-readable description
default-languagestringBCP 47 tag, used when a localized-string::plain carries no language
capabilitiesmapCapability declarations, keyed by capability id

On tool-definition.metadata — what a component says about each of its tools.

KeyTypePurpose
std:read-onlyboolDoes not modify state. Drives MCP readOnlyHint
std:idempotentboolSame arguments, same effect. Drives MCP idempotentHint
std:destructiveboolMay irreversibly modify state. Drives MCP destructiveHint
std:timeout-msuintSuggested timeout; the host may override
std:usage-hintslocalized-stringWhen to use this tool, for an agent
std:anti-usage-hintslocalized-stringWhen not to use it
std:examplesarray of bstrExample calls, as CBOR-encoded argument maps
std:tagsarray of stringCategorisation
std:session-opstring"open" / "close" — marks a tool synthesised by a transport adapter as a session lifecycle operation

open_session and close_session are synthesised by the MCP adapter for components exporting session-provider, so a component must not define tools with those names. On a collision the host suffixes its own (open_session__act) and warns.

May appear on any metadata field — a tool call, a list-tools response, a content part, an open-session.

KeyTypePurpose
std:session-idstringSession issued by session-provider. See Sessions
std:traceparentstringW3C Trace Context traceparent
std:tracestatestringW3C Trace Context tracestate
std:request-idstringCorrelation id for logging
std:progress-tokenstringMCP-compatible progress token
std:agent-idstringIdentifies the calling agent; informational, format implementation-defined

Transport adapters propagate std:traceparent and std:tracestate to and from the corresponding HTTP headers or MCP request extensions.

std:on-behalf-of is reserved for future use — usable with application-defined semantics, but not yet something to rely on across implementations.

On content-part.metadata, for reporting progress from inside a streaming result.

KeyTypePurpose
std:progressuintUnits completed so far
std:progress-totaluintTotal units, if known

Keys a component accepts in open-session.args — not in per-call metadata, which is discouraged for new designs because a credential repeated per call is a credential in the agent’s context per call. See Credentials.

KeyTypePurpose
std:api-keystringAPI key for the external service
std:bearer-tokenstringOAuth2/OIDC access token, or a generic bearer token
std:usernamestringBasic auth
std:passwordstringBasic auth
KeyTypePurpose
std:forwardobjectOpaque metadata blob passed to the next component in a chain; each bridge level unwraps one layer

On error.kind. See Troubleshooting for what to do about each.

KindMeaning
std:not-foundThe named tool does not exist
std:invalid-argsArguments or metadata failed schema validation
std:timeoutExceeded the declared or host-configured timeout
std:capability-deniedThe component used a capability that was not granted
std:session-not-foundA call referenced a session id the component does not recognise
std:credential-requiredA credential the component needs is absent from its profile. The host surfaces it with a command the user can run to provision it — neither the error nor the command describes the material
std:internalAn unrecoverable error inside the component

Keys of the std.capabilities map. See Policy & sandbox for the constraint shapes each one accepts.

IdParametersPurpose
wasi:http—Outbound HTTP
wasi:filesystemmount-root, mountsFilesystem access, plus the guest-path topology
wasi:sockets—Outbound TCP and UDP
act:credentials—The host credential store. A bare table; undeclared means denied

Third-party capabilities use their own namespace (acme:gpu/compute).

The ids above name resources the host mediates by interception. A semantic class names an action the host cannot see, because it travels over a channel the operator already permitted — db:drop, browser:navigate. They are declared like any other class and surfaced through act:consent.

They are component-defined: there is no registry of well-known ones, and none is reserved. Two components in different domains may pick the same identifier and neither is authoritative. Three rules hold regardless:

  • A class absent from the declaration is denied, and no grant widens it.
  • A declaration must name a concrete class. "db:*" is not a valid declaration — a reader could not tell what the artifact can ask for.
  • A class should separate irreversible actions from routine ones — db:drop apart from db:ddl — so the destructive case can be refused without refusing the rest.
[std.capabilities."db:drop"]
description = "Destructive operations (DROP, TRUNCATE)."
[[std.capabilities."db:drop".allow]]
key = "test_*"

ACT-CONSTANTS is normative and gets new keys first; this page is an index onto it.