tuffite0.1
THE CONTRACT, IN DETAIL

tuffite.json

A searchable configuration reference generated from the canonical schema.

Experimental source release. Production hardening and published SDK packages are still in progress.

The application manifest#

The root requires app and build. app defines identifier, security, and assets; build.shellApi defines code generation. productName and bundle are optional. Source and packaged application manifests have no schemaVersion. Unknown properties are rejected where additionalProperties is false. Validate with tuff check; type correctness alone does not guarantee route or permission semantics.

json
{
  "$schema": "https://tuffite.org/schema/v2/tuffite.schema.json",
  "productName": "My App",
  "app": {
    "identifier": "org.example.myapp",
    "security": { "capabilities": [] },
    "assets": []
  },
  "build": {
    "shellApi": { "namespace": "myapp", "definitions": ["shell_api.d.ts"] }
  }
}

Explore configuration types#

Fields, required markers, enums, unions, and references below come directly from schemas/tuffite.schema.json. Filter by field or type name. A missing default means the schema does not declare one.

Canonical JSON Schemaschema/v2

root

objectNo unknown fields
$schema
string

JSON Schema URL used by editor validation.

apprequired
app

Application identity, security, windows, native API, and assets.

buildrequired
build

Code generation, development package, web server, and debugging settings.

bundle
bundle

Resources included in the application package.

productName
string

Application display and bundle name; defaults to the Cargo package name.

Application display name and default bundle name. Defaults to the Cargo package name. Use a portable filename (up to 128 UTF-8 bytes); spaces and Unicode are supported.

app

objectNo unknown fields
identifierrequired
string

Application identifier, conventionally in reverse-domain form.

securityrequired
security

Content security policy and origin-scoped capabilities.

windows
window[]

Initial native window configurations.

assetsrequired
assetRoute[]

Explicit mappings from request origins/paths to resource files.

network
network

Application network policy.

utilities
object

security

objectNo unknown fields
csp
string

Frontend Content-Security-Policy.

Pattern: ^[^\r\n]+$

capabilitiesrequired
originCapability[]

Native permissions for explicitly matched origins.

window

objectNo unknown fields
labelrequired
string

Application-visible window label.

urlrequired
string

Initial page URL for the native window.

title
string
x
integer
y
integer
widthrequired
integer

Initial window width.

min: 1 · max: 16384

heightrequired
integer

Initial window height.

min: 1 · max: 16384

focused
boolean
decorations
boolean
minWidth
integer

min: 1 · max: 16384

minHeight
integer

min: 1 · max: 16384

maxWidth
integer

min: 1 · max: 16384

maxHeight
integer

min: 1 · max: 16384

build

objectNo unknown fields
devPackage
string

Directory of the refreshed native development package.

devUrl
string

Loopback frontend URL used by the authenticated dev override.

beforeDevCommand
string | object

Command started before the native development window.

beforeBuildCommand
string | object
devtoolsPort
integer

Loopback Chrome DevTools Protocol port.

min: 1 · max: 65535

profile
string
shellApirequired
object

Namespace and declaration files for typed code generation.

build.shellApi

objectNo unknown fields
namespacerequired
string

Pattern: ^[A-Za-z_$][A-Za-z0-9_$]*$

definitionsrequired
stringArray
facade
"application" | "framework"

bundle

objectNo unknown fields
executable
string
resources
stringArray

Application files and directories to include in the package.

icons
object

bundle.icons

objectNo unknown fields
macos
string

Project-relative .icns icon; defaults to Tuffite.

windows
string

Project-relative .ico icon; defaults to Tuffite.

originCapability

objectNo unknown fields
identifierrequired
string

Pattern: ^[A-Za-z0-9_-]+$

description
string
originsrequired
string[]
shellApi
shellApiEntry[]
explorer
object

originCapability.explorer

objectNo unknown fields
create
boolean
executeJavaScript
boolean

network

objectNo unknown fields
disableHttp2
boolean
maxResponseBytes
integer

min: 1 · max: 5242880

timeoutSeconds
integer

min: 1 · max: 300

assetRoute

objectNo unknown fields
originsrequired
string[]
pathsrequired
string[]
file
string
directory
string

shellApiEntry.variant2

objectNo unknown fields
methodrequired
string

Pattern: ^(?:\*|(?:[A-Za-z_$][A-Za-z0-9_$]*\.)+(?:[A-Za-z_$][A-Za-z0-9_$]*|\*))$

allow
value[]
deny
value[]