Optional ReadonlydisabledBare capability domains to remove from the delivered environment.
Optional ReadonlyresolveNarrow the live environment for one trusted creation-time identity.
The shell supplies copied, frozen live domains and named services. Returned names are intersected with that exact availability set, so this hook cannot add aliases, disabled entries, or unwired capabilities.
Identity assigned by the host when the iframe was created.
Immutable live domains and services before host policy.
The requested subset for this identity.
Optional host override for the static shell.init capability handshake.
Hosts normally advertise the default Kehto NAP surface. Development hosts may temporarily suppress domains to simulate smaller or policy-constrained shell environments while still using the production shell-ready path.