Forge documentation
Runtime concepts

Capabilities

Capabilities concepts mapped to actual Forge source packages.

An Arsenal capability token and a signing identity solve different problems. Validate authority, scope, time bounds and delegation before allowing an operation. Narrow capabilities for child agents and keep tool approval explicit. The SDK constructors can permit legacy identity-free mode; that is not an accountable deployment profile.

Implementation references

The references below are the Rust implementation. They include manifest versions, features, source hashes, and declarations.

Other languages

Use the language-specific package catalog for TypeScript, Python, Go, Swift and Kotlin. Similar responsibilities do not imply the same types, defaults, targets or deployed capabilities.

Validation

Read the exact package boundary and selected feature conditions. Run the relevant library tests and the applicable conformance fixtures before making a release claim. Source documentation and generated inventories do not replace runtime verification.

On this page