The widget runtime is the browser code every widget runs. It reads the widget’s manifest from window.WidgetSandbox.manifest, signs the reader in, exposes window.WidgetRuntime, and renders the built-in kinds. cef build, cef widget push, and cef dev inject the runtime and the manifest into your entry HTML; you do not add them yourself.
cef build vendors the runtime version that the installed CLI resolves, and logs it. Upgrade the CLI to ship a newer runtime.
window.WidgetRuntime
Method
Returns
Does
query(ref, params?)
Promise<QueryResult>
Runs a declared query by id. params bind to ? in its SQL, or are the tool’s arguments for a Memory Bank query.
publish(type, payload, context?, options?)
Promise<{ eventId }>
Publishes an event into the widget’s scope as the reader. options.target: <asPubkey>:<alias>, the one agent the event is for.
subscribe(context, opts, onEvents)
() => void (stop)
Follows one stream; onEvents receives each poll’s new events as an ordered batch.
identity()
Promise<Identity>
The reader’s identity.
connect()
Promise<Identity>
Signs the reader in.
connectAgent()
Promise<void>
Connects the widget’s agent to the reader’s vault.
subscribe delivers events already in the stream in its first batch, and each event once. It stops when you call the returned function or when the reader becomes anon.
Errors
Error
When
AgentNotConnectedError
A read for a reader whose vault has not connected the agent. Has agentId. Offer connectAgent().
WidgetSignedOutError
A framed widget’s host did not answer the identity handshake within 8 seconds, or answered malformed.
WidgetVaultUnreachableError
The host or link named a vault the widget cannot open. The runtime does not fall back to another vault.
WidgetWalletUnconfiguredError
A standalone widget’s manifest has no wallet origin.
Kinds
Set kind and config in the widget declaration; the runtime renders into #app.
{ groups, panels, defaultPanel, gating: { statusQuery, unlockWhen, firstRunPanel, hero? }, menu? }. Each panel holds any other kind, or { kind: 'custom', renderer, query? } drawn by a function registered with registerCompositePanel.
custom
Your own page.
Field formats: text, multiline, date, reltime, number, written as "column:format".
Manifest
The manifest cef writes into the entry HTML (WidgetManifest):
Field
Meaning
schemaVersion
1.
widgetId, name
Identity.
agentId
<asPubkey>:<alias>. Empty until --as-pubkey is given.
scope
The vault scope the widget reads and publishes in.
cubbyAlias
Default cubby for sql queries.
queries
{ id, label, sql?, cubby?, tool?, limit?, timeoutMs? }[]; tool is search, get, neighbours, or countByType.
events
{ type, schemaRef? }[].
kind, config
Built-in kind.
wallet
{ appId, env, origin }. origin is the Manykind passkey wallet used for standalone sign-in.
endpoints
vault, gar, marketplace, s3GatewayAuthInfo, rpc, from --env.
Sign-in
Opened
Identity source
In a frame
The host, over the postMessage handshake below. A framed widget never falls back to the standalone wallet.
Top-level
The Manykind passkey wallet at wallet.origin. An active session resumes silently; otherwise the runtime shows a sign-in control and opens the wallet on click. Reads use a delegation, so the reader is not asked to sign each request.
A link can name what to show, in its fragment (preferred) or query: vaultId or vault, runId or run, recordId or record. A named vault is still checked against the reader’s own access.