| RFC 0001: The RFC Process |
Governance |
Accepted |
| RFC 0002: Agent Identity and Reasoning Events |
Agent |
Accepted |
| RFC 0003: Agent Packs |
Agent |
Accepted |
| RFC 0004: Memory Layer |
Agent |
Accepted |
| RFC 0005: Multi-Turn Conversation |
Agent |
Accepted |
| RFC 0006: Run Orchestrator |
Agent |
Accepted |
| RFC 0007: Dispatch (`core.dispatch` Node Pattern) |
Agent |
Accepted |
| RFC 0008: WASM ABI for Cross-Language Node Packs |
Other |
Accepted |
| RFC 0009: Production-Profile Conformance |
Conformance |
Accepted |
| RFC 0010: Auth-Profile Conformance |
Auth |
Accepted |
| RFC 0011: Auth-Scoped Discovery Advertisement |
Auth |
Accepted |
| RFC 0012: Memory Compaction Profile |
Agent |
Accepted |
| RFC 0013: Workflow-chain packs |
Composition |
Accepted |
| RFC 0014: host.fs capability |
Host capability |
Accepted |
| RFC 0015: host.kvStorage capability |
Host capability |
Accepted |
| RFC 0016: host.tableStorage capability |
Host capability |
Accepted |
| RFC 0017: host.queueBus capability |
Host capability |
Accepted |
| RFC 0018: host.sql + host.vectorStore + host.searchIndex capabilities |
Host capability |
Accepted |
| RFC 0019: host.blobStorage + host.cache capabilities |
Host capability |
Accepted |
| RFC 0020: host-side MCP server composition |
Composition |
Accepted |
| RFC 0021: AI Envelope Primitive |
Envelope |
Accepted |
| RFC 0022: `core.dispatch` + `core.subWorkflow` runtime variable mapping |
Agent |
Accepted |
| RFC 0023: Conformance Agent-Event Emitters |
Agent |
Accepted |
| RFC 0024: Streaming `agent.reasoned` Deltas |
Agent |
Accepted |
| RFC 0025: Test-mode Registry Namespace |
Composition |
Accepted |
| RFC 0026: `provider.usage` Event |
Other |
Accepted |
| RFC 0027: Prompt Templates |
Other |
Accepted |
| RFC 0028: Prompt Library Endpoints + Prompt Pack Kind |
Composition |
Accepted |
| RFC 0029: Prompt Override Hierarchy + `agent.promptResolved` event |
Agent |
Accepted |
| RFC 0030: Envelope `reasoning` field + Tier 1 Structured-Output Subset (informative) |
Agent |
Accepted |
| RFC 0031: Envelope variant discrimination + model-capability declarations |
Envelope |
Accepted |
| RFC 0032: Envelope-reliability run-event vocabulary |
Envelope |
Accepted |
| RFC 0033: Envelope-completion contract (truncation vs schema-violation distinction) |
Envelope |
Accepted |
| RFC 0034: OTel collector test seam + secret-leakage invariant promotion |
Auth |
Accepted |
| RFC 0035: Sandbox execution contract for pack-loaded typeIds |
Composition |
? |
| RFC 0036: Multi-region idempotency + cross-engine append-ordering guarantees |
Other |
Accepted |
| RFC 0037: Multi-agent execution model + replay determinism under nondeterministic models |
Agent |
Accepted |
| RFC 0038: OpenWOP Working Group charter |
Other |
? |
| RFC 0039: Multi-agent execution model `version: 2` — confidence-threshold escalation + agent memory lifecycle |
Agent |
Accepted |
| RFC 0040: Multi-agent execution model `version: 3` — cross-host causation linking |
Agent |
Accepted |
| RFC 0041: Multi-agent execution model `version: 4` — replay determinism under nondeterministic models |
Agent |
Accepted |
| RFC 0042: Experimental capability tier |
Other |
Accepted |
| RFC 0043: Registry and extension-policy |
Composition |
Accepted |
| RFC 0044: Confidence-escalation interrupt-kind advertisement (clarification to RFC 0039 §A) |
Interrupt |
Accepted |
| RFC 0045: Connector pack manifest & action model |
Composition |
Accepted |
| RFC 0046: host.credentials capability — credential vault, encryption, sharing & rotation |
Other |
Accepted |
| RFC 0047: host.oauth — OAuth 2.0 authorization flows for connectors |
Auth |
Accepted |
| RFC 0048: Tenant · Workspace · Principal identity model |
Other |
Accepted |
| RFC 0049: RBAC scopes & authorization decisions |
Other |
Accepted |
| RFC 0050: SAML / SCIM (and optional LDAP) enterprise identity profiles |
Other |
Accepted |
| RFC 0051: Approval & deployment-gate primitive |
Other |
Accepted |
| RFC 0052: Scheduling & time-based triggers (promote + extend RFC 0017) |
Other |
Accepted |
| RFC 0053: Dead-letter routing & failure sinks |
Other |
Accepted |
| RFC 0054: Run diff & execution comparison |
Other |
Accepted |
| RFC 0055: Multimodal envelope variants & rendering hints (extend RFC 0031) |
Envelope |
Accepted |
| RFC 0056: Run feedback & annotation event (`run.annotated`) |
Other |
Accepted |
| RFC 0057: Memory write-attribution event (`memory.written`) |
Agent |
Accepted |
| RFC 0058: Run execution bounds (`runTimeoutMs` + `maxLoopIterations`) |
Other |
Accepted |
| RFC 0059: Agent workspace (`host.workspace`) |
Agent |
Accepted |
| RFC 0060: Host heartbeat capability (`host.heartbeat`) |
Other |
Accepted |
| RFC 0061: Stateful agent-loop lifecycle (`multiAgent.executionModel.version: 5`) |
Agent |
Accepted |
| RFC 0062: Scheduled memory distillation — "dreams" (`memory.distillation`) |
Agent |
Accepted |
| RFC 0063: Sub-run output attestation & merge gating (`core.subWorkflow.outputAttestation`) |
Other |
Accepted |
| RFC 0064: Tool invocation hooks & per-tool authorization (`host.toolHooks`) |
Other |
Accepted |
| RFC 0065: Workflow node primary-output annotation |
Composition |
Accepted |
| RFC 0066: `x-openwop-form` Vendor Extension on Pack `configSchema` |
Composition |
Accepted |
| RFC 0067: Provider-catalog conventions — provider-name vocabulary + BYOK auth-mode advertisement |
Auth |
Accepted |
| RFC 0068: Memory consolidation + standing commitments |
Agent |
Accepted |
| RFC 0069: Host-extension safety contract for `exec`-class tools |
Other |
Accepted |
| RFC 0070: Agent Manifest Runtime Capability (`agents.manifestRuntime`) |
Agent |
Accepted |
| RFC 0071: Artifact-Type Packs and AI Chat Card Packs |
Other |
Accepted |
| RFC 0072: Agent Inventory + Dispatch Normative Surface (amends RFC 0070) |
Agent |
Accepted |
| RFC 0073: Capability families are document-root properties of `/.well-known/openwop` |
Other |
Accepted |
| RFC 0074: Tenant-Scoped Manifest-Agent Inventory (amends RFC 0072) |
Agent |
Accepted |
| RFC 0075: Artifact-Type Packs — real-world adoption amendment (RFC 0071 Phase-1.1 erratum) |
Other |
Accepted |
| RFC 0076: Pack runtime-requirements declaration + host-provided safe-fetch |
Composition |
Accepted |
| RFC 0077: Agent Run Lifecycle + Live Manifest Dispatch |
Agent |
Accepted |
| RFC 0078: Portable Tool Catalog + Tool Session Contract |
Other |
Accepted |
| RFC 0079: Credential Provenance + Egress Policy |
Other |
Accepted |
| RFC 0080: Agent Memory Capability Reconciliation |
Agent |
Accepted |
| RFC 0081: Agent Evaluation, Scorecards, and Promotion Gates |
Agent |
Accepted |
| RFC 0082: Agent Deployment Lifecycle |
Agent |
Accepted |
| RFC 0083: Durable Trigger + Channel Bridge Profile |
Other |
Accepted |
| RFC 0084: Budget, Quota, and Cost Policy |
Other |
Accepted |
| RFC 0085: `openwop-agent-platform` Meta-Profile |
Agent |
Accepted |
| RFC 0086: Standing Agent Roster + Workflow Portfolio |
Agent |
Accepted |
| RFC 0087: Agent Org-Chart |
Agent |
Accepted |
| RFC 0088: `openwop-core-standard` — the stable Core Standard Profile |
Other |
Accepted |
| RFC 0089: Conformance certification bundle — machine-readable per-profile evidence |
Conformance |
Accepted |
| RFC 0090: Agent verifier turn + convergence criteria (multi-agent execution `version: 6`) |
Agent |
Accepted |
| RFC 0091: Multimodal perception input on `ctx.callAI` (typed content parts) |
Other |
Accepted |
| RFC 0092: Agent-level capability requirements (`AgentManifest.requiresCapabilities`) |
Agent |
Accepted |
| RFC 0093: Protocol hardening — webhook delivery egress, interrupt-token lifecycle, retryable-response caching, approval-gate timeout semantics |
Auth |
Accepted |
| RFC 0094: Wire-shape reconciliation — schema/prose defect repairs and forward-compat closure policy |
Envelope |
Accepted |
| RFC 0095: Connection packs — portable provider definitions |
Other |
Accepted |
| RFC 0096: Reviewable Learning — Skill/Automation Proposal Lifecycle |
Other |
Accepted |
| RFC 0097: Standing Goals and Judge-Based Continuation |
Other |
Accepted |
| RFC 0098: Agent Platform Portability — Export Bundle and Tenant Import |
Agent |
Accepted |
| RFC 0099: External-Event Trigger Ingestion (webhook / email / form sources) |
Transport |
Accepted |
| RFC 0100: Async / Durable A2A Tasks — durable task persistence, streaming + push for cross-host handoffs |
Other |
Accepted |
| RFC 0101: Multi-party group conversation (shared transcript, speaker attribution) |
Agent |
Accepted |
| RFC 0102: A2UI agent-authored interface surfaces |
Agent |
Accepted |
| RFC 0103: Localized Content Surface — durable, authored, structured localized content (pages → sections) extending the Stable i18n annex |
Other |
Accepted |
| RFC 0104: Portable HITL approver routing |
Interrupt |
Accepted |
| RFC 0105: Speech synthesis adapter (`ctx.callSpeechSynthesizer`) — text-to-speech as a first-class AI provider sub-capability |
Other |
Accepted |
| RFC 0106: Real-time voice session profile — streaming transcription, streaming synthesis, and the turn-taking / barge-in event taxonomy |
Other |
Accepted |
| RFC 0107: Publishable declarative pack kinds (registry version manifest) |
Composition |
Accepted |
| RFC 0108: Self-hosted / OpenAI-compatible provider class (`aiProviders.selfHosted[]`) |
Other |
Accepted |
| RFC 0109: Conversation-turn model provenance (`agent.model`) |
Agent |
Accepted |
| RFC 0110: Channel presence (online + typing) |
Other |
Accepted |
| RFC 0111: Context Economy — Transcript Token Budget & Declared Summarization |
Auth |
? |
| RFC 0112: Compact Tool Projection |
Other |
Accepted |
| RFC 0113: Memory Injection Budget |
Agent |
Accepted |
| RFC 0114: A2UI Surface Deltas |
Other |
Accepted |
| RFC 0115: Run Transport Economy |
Transport |
Accepted |
| RFC 0116: Portable Prompt-Prefix Cache |
Other |
Accepted |
| RFC 0117: Front-End Plugin Packs (Sandboxed UI Extensions) |
Other |
Accepted |
| RFC 0118: Parallel Sub-Workflow Fan-Out and Join |
Composition |
Accepted |
| RFC 0119: Front-End Plugin Isolation as a Mechanism-Neutral Property (amends RFC 0117) |
Other |
Accepted |
| RFC 0120: Connection-pack provider `apiHosts` — declared credential-egress allow-list |
Composition |
Accepted |
| RFC 0121: Subscription-reuse provider auth mode (`aiProviders.authModes: "subscription"`) |
Auth |
? |
| RFC 0122: Self-hosted runner (remote-driven local execution) |
Other |
Accepted |
| RFC 0123: Connection-pack provider `vendor` — catalog grouping |
Composition |
Accepted |
| RFC 0124: Portable per-run parameter deferral for workflow-chain packs |
Composition |
Accepted |
| RFC 0125: Chain-pack `FragmentEdge.triggerRule` (fan-in / error-routing for workflow-chain packs) |
Composition |
Accepted |
| RFC 0126: Data-parallel `core.dispatch` — per-item input fan-out |
Agent |
Accepted |
| RFC 0127: Streaming & CDC trigger sources |
Other |
Accepted |
| RFC 0128: Purpose-propagation — permitted-use labels on synced data |
Other |
Accepted |
| RFC 0129: Data-residency — regional advertisement + honor-or-reject run constraint |
Other |
Accepted |
| RFC 0130: Canvas Preview Plugin Surface (amends RFC 0117) |
Other |
Accepted |
| RFC 0131: Agent-manifest `role` and the Skill profile |
Agent |
Accepted |
| RFC 0132: Anonymous-actor authorization for public agent surfaces |
Agent |
Accepted |
| RFC 0133: Workflow-chain composition — sub-chains and produced variables |
Composition |
Accepted |
| RFC 0134: Edge conditions — `truthy` / `falsy` operators |
Other |
Accepted |
| RFC 0135: Workflow-chain gallery visibility — `internal` chains |
Composition |
Accepted |
| RFC 0136: `WorkflowVariable.format` — a presentational hint for run inputs |
Composition |
Accepted |
| RFC 0137: Form-content packs — a publishable declarative pack kind for form templates |
Composition |
Accepted |
| RFC 0138: Vendor-extension hatch on pack manifests |
Composition |
Accepted |
| RFC 0139: Host-side witness for pack-manifest extension opacity |
Composition |
Accepted |
| RFC 0140: Replay side-effect suppression — a run replayed MUST NOT re-fire its external effects |
Other |
Accepted |
| RFC 0141: Legacy artifact-type identifiers — never-conformant status and the replay migration constraint |
Other |
Accepted |
| RFC 0142: The `store`-gated `artifact.created` emission witness |
Other |
Accepted |
| RFC 0143: Tool-result trust is untrusted-by-default and monotone through composition |
Composition |
Accepted |
| RFC 0144: Which host capability families the core schema declares |
Host capability |
Accepted |
| RFC 0145: `registrationSource` as a per-type artifact capability facet |
Other |
Accepted |
| RFC 0146: `contractProvenance` — which corpus revision a host implements against |
Other |
Accepted |
| RFC 0147: Protocol Integrity and Standards-Readiness Program |
Other |
Accepted |
| RFC 0148: Non-Vacuous Conformance and Certification Evidence |
Conformance |
Accepted |
| RFC 0149: Machine-Contract and Version Reconciliation |
Other |
Accepted |
| RFC 0150: Effect Identity, Replay, and Split-Brain Safety |
Other |
Accepted |
| RFC 0151: Compensation and Partial-Failure Profile |
Other |
Accepted |
| RFC 0152: A2A 1.0 Versioned Composition |
Composition |
Accepted |
| RFC 0153: MCP 2026-07-28 Versioned Composition |
Composition |
Accepted |
| RFC 0154: Workload Identity, Delegation, Telemetry, and Provenance Assurance |
Envelope |
Accepted |
| RFC 0155: Core Profile and Extension Discipline |
Other |
Accepted |
| RFC 0156: Governance, Independent Assurance, and Claims Policy |
Governance |
Accepted |
| RFC 0157: Chain fragments carry compensation (RFC 0013 revision × RFC 0151 §B) |
Composition |
Accepted |
| RFC 0158: Durable Execution and Disaster-Recovery Qualification |
Other |
Active |
| RFC 0159: SCIM ⟷ SAML subject linking (the combined-deployment leaver contract) |
Other |
Accepted |
| RFC 0163: SCIM ⟷ SAML subject-linking hardening |
Other |
Accepted |
| RFC 0164: Mandatory SCIM ⟷ SAML subject linking for combined hosts |
Other |
Accepted |
| RFC 0165: v2 preparation — additive wire shapes (`protocolVersions[]`, the Subject record, header dual emission) |
Other |
Accepted |
| RFC 0166: Register dispositions, terminal RFC states, and witness classes on the assurance registers |
Other |
Accepted |
| RFC 0167: OpenWOP v2 — the program RFC |
Other |
Active |
| RFC 0168: v2 evidence and conformance — requirement ids in source, witness class on every requirement, seams as a versioned profile evicted from the canonical API, two products in two ledgers, a suite that ships only the suite, and bundle v3 closed and signed |
Conformance |
Active |
| RFC 0169: v2 discovery and capabilities — one record type, a closed root, one declaration file, derived profiles |
Other |
Accepted |
| RFC 0170: v2 identity — Subject required, one binding pipeline per lane, the link as a typed record, grammars for every id and handle, token agility |
Auth |
Active |
| RFC 0171: v2 wire envelope — one closed event envelope and payload registry, one error registry, one header scheme, a closed `configurable`, one poll cursor |
Composition |
Active |
| RFC 0172: v2 versioning and release — major negotiation, one origin, every axis dispositioned, one release identity |
Other |
Active |
| RFC 0173: v2 security defaults — an obligation of the surface, never a discovery flag |
Other |
Active |
| RFC 0174: v2 governance — terminal states used, the Accepted predicate as a machine, waiver authority checked at merge, the front door under budget |
Governance |
Accepted |
| RFC 0175: v2 transports and embedded protocols — gRPC demoted or generated, the legacy A2A and MCP profiles gone, negotiation authenticated with a minimum-version policy, the interop threat model written |
Transport |
Active |
| RFC 0176: v2 persisted data and coexistence — the event-log translation contract as data, the v1-pinned-run disposition, one well-known resource for both majors, a per-store disposition for every table both hosts persist, and the corpus-tag pin |
Other |
Active |
| RFC 0177: v2 registry, packs, and the extension tail — the absent-ceiling rule, a parallel `registry/v2/` tree, the peer-dependency alias table generated from the declaration file, one signing scheme, the vendor hatch on every pack-authored document, and the chain / form / connection decisions three gap tables deferred |
Composition |
Active |
| RFC 0178: v2 assurance registers and deprecation machinery — removal dates that bite, one gap namespace with witnesses, falsifiability as data, hygiene the cut does not carry forward |
Other |
Accepted |
| RFC 0179: Root `preferredVersion` — the v1.x additive half of protocol-major negotiation |
Other |
Active |
| RFC 0180: Vendor-org registration — the procedure the registry never had |
Composition |
Active |
| RFC 0181: Vendor path namespace — `/host/<org>/…` for host-proprietary operations under major 2 |
Other |
Accepted |
| RFC 0182: `listRuns` — a portable, tenant-scoped, paginated run list under major 2 |
Other |
Accepted |