Invoke an operation a registered extension exposes
The generic request lane for extension-defined behaviour, and the near half of the registered extension’s own invoke operation: a client reaches an extension THROUGH this host, needing nothing but the extension’s name and never holding its secret. The host signs the forwarded call under the registration’s secret, judges the address on the way out and refuses a redirect; the payload is the extension’s own contract and the host only routes it.
The address is configuration, not a credential. listExtensions shows endpoint to every member of the organisation on purpose — a registry that hid where an extension points would answer “what is reading our conversations” with less than the truth — so what this lane withholds is the secret and the signature, not the URL. Knowing the address buys nothing without the secret: every call in the extension contract is signed, and an extension is required to refuse anything that does not verify.
An ordinary member’s token is enough. Invoking is using, and only registering is owning — extensions:manage gates the writes that create, re-point, revoke and re-order a registration.
The forward runs under the same deadline a transformation gets.
Autorizaciones
Enforced on every transport, with no exempt operation. A person's request — over the default local unix socket exactly as over a TCP listener — must carry a JWT issued by the configured identity provider, which the host verifies itself against that issuer's key set: signature, issuer, expiry, and the person and organisation it names. Requests without a valid one receive 401 NRY-0011. The socket's file permissions are transport and are not an authorisation.
Parámetros de ruta
The extension's namespaced name, publisher/extension form.
^[a-z0-9][a-z0-9-]*\/[a-z0-9][a-z0-9-]*$"lerian/ring-review"
Cuerpo
Respuesta
The operation's result, as the extension defined it.
The operation's result, as the extension defined it.
Free-form output — the extension's own contract.

