KRATON
Open navigation menu

Kraton Registry / discovery plane

Find a VMC. Pin its bytes.

Search intent, browse declared authority, then inspect one immutable record by digest. This is a registry surface — not a gallery of claims.

SEMANTIC SEARCH · HARD AUTHORITY FILTERS · SIGNED + VERIFIED RECORDS ONLY

Allowed authority / hard filter

A filter is an allowlist: a result's declared capabilities must be a subset of the chosen boundary. These are not decorative tags or relevance hints.

How a VMC binds policy

Registry records

Latest verified records.

DISCOVERY STATUS / OFFLINE

Discovery API unavailable

The registry does not invent records while its source is absent.

The read-only discovery service is offline. Artifact bytes, review state, and registry entries remain intentionally absent here until the service can answer again.

Reset browse

A record has a lifecycle

Publication is not a button in discovery.

GraphQL is intentionally read-only. Publishing follows a separate authenticated path: the component is inspected, its boundary is analysed, its bundle is signed, and only then can a record become discoverable.

01

Publish

Send the candidate artifact through the authenticated publish path.

02

Extract

Read WIT, schemas, and imports from the component bytes.

03

Analyse

Derive capabilities and reject boundaries that do not hold.

04

Sign

Bind component and policy layers in one artifact bundle.

05

Discover

Expose a signed, verified record addressed by digest.

The digest is the contract between planes.

Discovery returns a SHA-256 address; OCI serves those exact bytes; the Engine runs that exact address. A name may advance. A digest never silently does.

Admission is not a badge

A claim arrives before it earns a place in discovery.

The authenticated publisher path is deliberately separate from browsing. A newly accepted artifact stays pending until its component, declared authority, signature, and analysis result agree.