Open source

The spec is open. The network is a product.

One register, read from flashyos.com and rendered here with each tool’s documentation beside it. A repository is linked only when it has been read as public; a package is listed as held only with the reason it waits.

30 published · 16 held · 1 of 39 open-licensed repositories read as public · register accepted 2026-10-04 · the door: Open source on flashyos.com

Published · 30

PackageWhat it isVersionHere
@flashyos/aaoThe AAO manifest and charter format, naming standard and conformance suite — what makes an organization an Agentic Autonomous Organization on the DeAI Operating System.0.4.2edge cases →
@flashyos/agentReport agent state to the FlashyOS mesh — the DeAI Operating System for Agentic Autonomous Organizations (AAOs).0.21.0edge cases →
@flashyos/artifactartifact/1 — a dated public commitment to content nobody can read yet. Existence precedes discovery.0.1.0edge cases →
@flashyos/assetmeshrwa/1 — a machine-readable record of a real-world asset, the attestations that stand behind it, and the obligations issued against it. Dependency-free, publishable at your own domain, verifiable by anyone.0.1.0edge cases →
@flashyos/backlogbacklog/1 — the future tense of a record. One item per intention, filed where the work happens, emitted as a fragment per repository and merged into one list across an estate or a portfolio. Filed is private, publication takes a named human, and every item decays.0.1.1edge cases →
@flashyos/boltbolt/1 — one secret, split across an estate. A hunt verified by commitment, in the finder's own browser.0.2.2edge cases →
@flashyos/canoncanon/1 — a lockfile for facts. One authority per fact, fetched by every property that renders it, with drift as a build failure rather than a silent update.0.1.0edge cases →
@flashyos/checkpointcheckpoint/1 — a Merkle tree head over the sealed claims an organisation already publishes. RFC 6962 hashing, inclusion and consistency proofs, verifiable offline against the fragments themselves.0.2.0edge cases →
@flashyos/conformanceRun the FlashyOS conformance suite against any domain, or audit your own charter and handshake offline. Scaffolds a new property to L2 with one command. Exit 0 only when the level you asked for is actually met.0.2.3edge cases →
@flashyos/countersignVerification over a directory/1 record: a countersignature from the party a claim is about, an audit of what a website can prove, and a badge that carries a date. Ed25519 over the canonical assertion, verifiable offline from two published keys.0.1.0edge cases →
@flashyos/create-mesh-agentScaffold a dependency-free FlashyOS mesh starter agent into your repo — a standing worker that heartbeats, works your org's approved joint-initiative tasks (you supply the evidence), and surfaces roadmap matches, in one file. Agents suggest, humans consent; the agent completes work but never seals.0.2.0edge cases →
@flashyos/create-mesh-nodeJoin the FlashyOS mesh in one command — scaffolds a charter, handshake, directory fragment and emit workflow, then verifies you pass L2 before it finishes. No account, nothing published.0.1.0edge cases →
@flashyos/deliverydelivery/1 — the rungs between a merged commit and a thing somebody actually has. Published, distributed and linked are measured by fetching, never declared.0.1.0edge cases →
@flashyos/dialectsOne charter, many dialects — emits the surfaces other standards define (agents.txt/agents.json, A2A Agent Card) from an organisation's AAO charter, so the same facts cannot drift between them. Refuses to emit a surface the organisation does not serve.0.1.0edge cases →
@flashyos/directoryThe estate directory — one record per real thing, emitted as fragments by each repository and merged into a single world model every property renders a view over.0.2.0edge cases →
@flashyos/eslint-configThe estate's shared ESLint base. One config every property extends, so a lint rule is argued once.0.1.0edge cases →
@flashyos/frontdoorfrontdoor/1 — a published door: which lanes an organisation opens, what it asks at each, and what it owes in return. Emitted per repository, validated across an estate, verified from the applicant's own domain.0.1.0edge cases →
@flashyos/holdingholding/1 — a log of what happened to the positions an office holds. Transitions rather than states, consent enforced rather than asserted, and no currency figures in version 1.0.1.0edge cases →
@flashyos/llm-gatewayProvider-agnostic inference seam: adapters, automatic failover, and an empty-success guard. One package so the estate stops carrying copies.0.2.1edge cases →
@flashyos/llms-txtParse, validate, and build llms.txt files — machine-readable site metadata for the DeAI web, extracted from the tooling every Flashy property ships in production.0.1.1edge cases →
@flashyos/mailmail/1 and the estate's mail control plane: a lane policy that refuses, a capture that demands a consent basis, a content-free event record, and a transport seam so the provider is a variable.0.3.0edge cases →
@flashyos/mcpModel Context Protocol server for FlashyOS — connect any MCP-speaking agent to the mesh in one config block. Wraps @flashyos/agent.0.6.0edge cases →
@flashyos/meshOne checklist for joining the mesh — what a repository has adopted, what is left, and the command for each.0.1.0edge cases →
@flashyos/pageOne page, one card, one claim — per-page social images, canonical metadata and structured data for a property that expects to be cited by search engines and answered from by generative ones.0.1.1edge cases →
@flashyos/playbookplaybook/1 — a way two or more organisations work together, as a published document rather than code. Named roles, ordered steps, and an evidence kind per step. Authored by an org, served at its own domain, adopted by reference.0.2.0edge cases →
@flashyos/shiplogshipped/1 — the past tense of a record. One sealed entry per thing that shipped, emitted per repository and merged into one cross-repository calendar, changelog and attribution report. Verifiable offline; the past is append-only.0.1.0edge cases →
@flashyos/signerThe isolated signer for the FlashyOS wallet authorization plane: verifies an Ed25519-signed SpendAuthorization, re-derives the operation from the real call, refuses on any mismatch, executes through Tether WDK, and reports settlement. Holds the seed; never holds the plane's private key.0.1.0edge cases →
@flashyos/verifyRe-verify every sealed settlement on the FlashyOS network: fetch the public feed, recompute each sha256, exit 0 only if the books check out. Verify, don't trust — including us.0.5.0edge cases →
@flashyos/wallet-wdkGoverned economic agency for FlashyOS agents on Tether WDK: the AAO WalletCapability, a FlashyOS authorizer client, an MCP elicitation handler, and a WDK policy rule that defers to the authorization plane.0.1.0edge cases →
@flashyos/wdkThe FlashyOS agent object: identity, authority, wallet, memory and partners behind one interface. Create an agent, give it an identity, provision financial capabilities on Tether WDK, set its permissions, let it transact, record what it did, coordinate it with other agents — through one object, one event system, any chain WDK reaches.0.1.0edge cases →

Held · 16 until a first adopter

Apache-2.0 in the tree and deliberately off every registry. A format is published on its first adopter, never before: a package with no user outside the estate would be a promise about stability nobody has tested. Each carries the reason it waits.

PackageWhy it waits
@flashyos/alchemyA format is unpublished until its first adopter — the estate's own rule, which reward/1, wallet/1, ritual/1, pulse/1 and deploy/1 all obey. alchemy/1 has exactly one world today and it is ours, so a registry listing would be adoption theatre. It publishes on the day a second party writes a ruleset, which is also the day the vocabulary stops being ours alone and starts being worth agreeing on.
@flashyos/computeNot published, and the reason is the format's own subject. compute/1 records the inference compute an AAO spent per initiative, and the estate has spent none through the seam yet — LLM_PROVIDER has never been flipped to gatewayz outside tests, so every history the format would carry today is empty or uncaptured. Publishing a package for a per-initiative compute history when no initiative has captured compute is a registry entry for a thing nobody does, which is the adoption theatre this estate measures elsewhere. The estate's rule for exactly this is written down repeatedly: publication on the first adopter, never before. The vendored emitter travels by file copy, which is how every record format here actually travels, so being unpublished costs an adopter nothing.
@flashyos/definedNot published, and the reason is this family's own rule for formats: publication on the first adopter, never before. No party outside the estate this was written in publishes a defined/1 fragment yet, so a package on a registry would be adoption theatre. The vendored file travels by copy, which is how every record format here actually travels, so being unpublished costs an adopter nothing.
@flashyos/deployNot published, and by the same rule reward/1 carries: publication on the first adopter, never before. deploy/1 is a format and a dependency-free checker meant to be vendored into any repository that serves a domain, and no party outside this estate declares one yet — so a registry entry today would be a package for a thing nobody does, which is the adoption theatre this estate measures elsewhere. Apache rather than AGPL because a checker a party can only run under copyleft is one the parties who most need to declare a deployment cannot embed.
@flashyos/estate-ringNot published, and the reason is the estate's own rule for formats: publication on the first adopter, never before. No organisation outside this estate reads an interlink ring as estate-ring/1 yet, so a package on a registry would be adoption theatre. The vendored emitter travels by copy, which is how every record format here actually travels, so being unpublished costs an adopter nothing; the ring the footer renders is the served document, not the package.
@flashyos/guardianNot published, and the reason is independence as much as adoption: a guardian is only worth anything if it runs somewhere the guarded code cannot reach, and no organisation outside this repository deploys one yet. Publishing the shape before a second deployment exists would be a package for a thing nobody does, which is the adoption theatre this estate measures elsewhere. It becomes public with the first guardian deployed by a party other than the one it guards.
@flashyos/pinnedPublished on the first external adopter, never before — the estate's rule for every record format. pinned/1 is adopted INSIDE the estate today by vendored file copy (flashy.academy's content-graph gate consumes it; flashyos pins its own derived docs through tools/pinned.mjs), which is how every record format here actually travels: node: builtins only, copied byte-for-byte, no install. A registry entry for a standard nobody outside has adopted is the adoption theatre this estate measures against, so it stays private until someone outside asks to install it — at which point being unpublished has cost that adopter nothing.
@flashyos/pulseNot published, and by the same rule deploy/1 carries: publication on the first adopter, never before. pulse/1 is a format and a vendored emitter, and no adopter outside this estate keeps a condition series yet — the command centre reads the workspace directly and the vendored file travels by copy, so publishing now would be a registry entry for a thing nobody does. Apache rather than AGPL because a format for measuring your own estate is worth nothing if the parties measuring theirs cannot embed it.
@flashyos/registerNot published, and the reason is the estate's own rule for formats: publication on the first adopter, never before. No organisation outside this estate publishes a register yet, so a package on a registry would be adoption theatre. The vendored file travels by copy, which is how every record format here actually travels, so being unpublished costs an adopter nothing. The FRAGMENT is served publicly today; that is the document, not the package.
@flashyos/rewardNot published, and the reason is the format's own subject. reward/1 describes entitlements that cannot be paid until a settlement venue exists, and no venue exists — Flashy Finance's shared wallet is the venue and it has not been built. Nothing in this estate emits the format, so publishing it would put a package on a registry for a thing nobody does yet. The estate's rule for exactly this is written down twice: publication on the first adopter, never before. The vendored emitter travels by file copy, which is how every record format here actually travels, so being unpublished costs an adopter nothing.
@flashyos/ritualNot published, and the reason is the estate's own rule for formats: publication on the first adopter, never before. Nothing outside this estate observes a liturgy yet, so a package on a registry would be adoption theatre. The vendored file travels by copy, which is how every record format here actually travels, so being unpublished costs an adopter nothing.
@flashyos/standingNot published, and the reason is doctrine as much as adoption: a trust figure is the most tempting derived field this estate will ever hold, and the decision on who may see one is private-tier, promote-only, refused by name in every validator. No organisation outside this repository computes standing/1 yet, so a registry entry would be adoption theatre; and until the figure's visibility rule has a first adopter, publishing the function invites publishing the number.
@flashyos/tallyNot published, and the reason is the estate's own rule for formats: publication on the first adopter, never before. No organisation outside this estate publishes a tally yet, so a package on a registry would be adoption theatre. The vendored file travels by copy, which is how every record format here actually travels, so being unpublished costs an adopter nothing.
@flashyos/voiceNot published, and the reason is the estate's own rule for formats: publication on the first adopter, never before. gda-group is voice/1's first real adopter and it takes the file by copy, not by installing this package, so a registry listing would be adoption theatre before any second repository has asked for one. The vendored file travels by copy, which is how every convention in this estate actually travels, so being unpublished costs an adopter nothing.
@flashyos/walletNot published, and the reason is the format's own subject. wallet/1 describes a holding that becomes spendable only once a venue declares itself operational and cites an invariant run that passed. Flashy Finance is that venue and it is being built; no fragment in this estate declares an operational one. Publishing the package now would put a wallet contract on a registry ahead of the thing that honours it, which is the failure this format exists to refuse, made one layer up. The estate's rule for exactly this is written down twice: publication on the first adopter, never before. The vendored emitter travels by file copy, which is how every record format here actually travels, so being unpublished costs an adopter nothing.
@flashyos/workflowNot published, and the reason is the estate's rule for formats: publication on the first adopter, never before. workflow/1 is new in V2-D and no organisation outside this repository runs a workflow through it yet; the invoice-to-payment scenario in its own tests is the only adopter. A registry entry for a format nobody runs would be adoption theatre, which the estate measures elsewhere. It becomes public the day a second property executes a definition it did not write.

Public repositories · 1

38 more open-licensed repositories are in the register and not linked here: their visibility is private or has not been read. Unread is not public, and a link a stranger cannot open is a claim.

Planned, with status · 5

RepositoryPackageStatus
FlashyLabs/agentfileagentfilenot released Not released. The formats it writes are published and stable; the seven questions and the writer are the work that remains. Nothing here is installable yet.
FlashyLabs/conformance-kit@flashyos/conformance-kitnot released Pre-1.0. The line protocol is the part worth freezing and it is deliberately tiny: `{id, set, input, context?}` in, `{id, valid, codes?}` out. It will be locked at 1.0 and has not changed since it was written.
FlashyLabs/flashyos-spec—not released The specifications are not here yet. They are Apache-2.0 today; carrying the packages out of the monorepo they were written in, *with their real commit history*, is a deliberate operation rather than a copy — a chain of title that begins on the day somebody remembered to copy the files is not a chain of title. Until that runs, this repository is the licence, the security policy and the direction.
FlashyLabs/flashyos-tools@flashyos/toolsnot released Pre-1.0. `served` and `reachability` have been running against a thirty-eight repository estate for months; the API is small and unlikely to move, but the version says 0.x until somebody outside that estate has depended on it.
FlashyLabs/mesh-lint@flashyos/mesh-lintnot released Not released. The code is here; the distribution is not. The three checks run, are tested against fixtures rather than against the estate that found them, and `action.yml` is a composite action with no build step. What does not exist yet is a published package or a tag — measured 2026-09-23, `@flashyos/mesh-lint` answers 404 on npm and this repository has no tags — so `npx @flashyos/mesh-lint` and `uses: flashylabs/mesh-lint@v1` both fail today. Clone it and run `node src/cli.mjs` until they do. That gap is named here rather than left for the first person who copies a line out of the section above, which is the same defect this package's own `well-known` check exists to find.

Licence

Everything on this page is Apache-2.0, holder Flashy Labs. The estate’s two licences and the boundary between them (the spec and clients Apache-2.0; hosted applications AGPL-3.0-only; Apache code may never consume AGPL code) are declared once, in flashyos’s licence register, and a test there holds the direction. Client work is never open-licensed and never appears here.

Contribute

A pull request needs a Developer Certificate of Origin sign-off, not a contributor agreement. Every format has a conformance corpus; a parser in any language that accepts and rejects the same documents ours does is a conforming implementation, and the corpus is the contract. Report a defect by filing it at /engage; a security finding goes to the address in each repository’s SECURITY.md, never to a public issue.