Skip to content

Kehto Runtime Toolkit Documentation ​

Kehto is an unopinionated toolkit and protocol kernel for building NIP-5D napplet runtimes. It supplies reusable host-side machinery without choosing one origin, signer, or deployment policy for every implementer. Paja is Kehto's reference developer runtime; the playground is a visualization and verification fixture.

Alpha status: NIP-5D is still under development, and NAP contracts are not final. Package APIs, capability names, requires declarations, and injected-domain behavior may change as the spec evolves. See Alpha Status.

Kehto provides host-side packages that let a Nostr client embed sandboxed napplet iframe applications: access control, protocol dispatch, browser shell integration, service building blocks, relay discovery, and shell-owned window-management contracts.

Kehto works with the @napplet packages. @napplet/core, @napplet/shim, @napplet/nap, and @napplet/vite-plugin define the portable napplet-side protocol and build surface. Kehto consumes those contracts and provides runtime and shell implementation tools.

Start Here ​

ReaderStart pathWhat you are trying to do
Host-app implementerRuntime implementation guideBuild a shell that hosts sandboxed napplets.
Protocol evaluatorAlpha statusUnderstand what remains draft-stage and distinguish Kehto's toolkit from Paja's reference choices.
Package API consumerPackage referenceUnderstand one @kehto/* package and its exports.
Napplet authorNapplet integration tutorialDeclare requires, check injected domains, and use NAP helpers safely.
MaintainerDocs maintenance guideKeep README, site, API reference, and milestone history aligned.

Package Map ​

PackageRole
@kehto/aclPure capability state and enforcement primitives.
@kehto/runtimeBrowser-agnostic protocol engine, dispatch, ACL gates, service registry, and lifecycle.
@kehto/shellBrowser adapter: iframe/session lifecycle, postMessage, gateway loading, injected window.napplet domains, and shell policy.
@kehto/servicesReference service handlers for identity, relay, keys, media, notify, config, resource, cache, theme, and audio.
@kehto/nipFramework-agnostic unique Nostr NIP utilities (NIP-51 lists, NIP-65 outbox, NIP-66 relay discovery, NIP-89 app handlers).
@kehto/wmStructural window-management contracts for consumer-owned layout strategies.
@kehto/pajaReference developer runtime with concrete browser and service policies.
@kehto/playground9-napplet protocol visualization and Playwright verification target.

Current Documentation Shape ​

  • Start explains the project, packages, and reader routes.
  • Concepts explain architecture, security boundaries, capability negotiation, and source-of-truth decisions.
  • Napplet Web Cache Strategy explains the recommended browser cache layer and eviction policy for verified napplet artifacts.
  • Implement a Napplet Artifact Cache shows how to wire the shipped @kehto/nip/5d Cache Storage adapter into a host resolver.
  • Tutorials walk through complete implementation paths.
  • How-tos answer focused operational tasks.
  • Package Reference documents each public package and links to generated API pages.
  • API Reference links to generated TypeDoc output under docs/api/.
  • Policies host current shell/NIP-5D policy documents.
  • Migration Archive keeps historical transition documents clearly marked as non-current guidance.

Historical Material ​

Documents under docs/migrations/ are preserved for project history. They describe already-shipped transitions and should not be used as current integration guidance unless a current guide links to a specific section deliberately.