Read one registered extension
One registration, never its secret. Readable by any member, for the listing’s reason.
Autorizações
Enforced on every transport, with no exempt operation. A person's request — over the default local unix socket exactly as over a TCP listener — must carry a JWT issued by the configured identity provider, which the host verifies itself against that issuer's key set: signature, issuer, expiry, and the person and organisation it names. Requests without a valid one receive 401 NRY-0011. The socket's file permissions are transport and are not an authorisation.
Parâmetros de caminho
The publisher half of the extension's namespaced name.
The name is publisher/extension and travels as TWO path segments rather than one. The single-segment spelling is not broken — a generated client percent-encodes a path parameter's slash and the router decodes it back — so this is a deployment choice rather than a repair: an encoded slash is normalised or rejected by most reverse proxies a hosted home sits behind, and two segments read the way the name reads, /v1/extensions/lerian/redactor.
^[a-z0-9][a-z0-9-]*$"lerian"
The extension half of the namespaced name.
^[a-z0-9][a-z0-9-]*$"redactor"
Resposta
The registration.
An extension this host carries: a program this home REGISTERED at an HTTPS address. Never its secret, on any response that uses this schema.
package is absent on a registered extension, which has no package — it is another deployment rather than anything installed here.
Namespaced name, publisher/extension form.
^[a-z0-9][a-z0-9-]*\/[a-z0-9][a-z0-9-]*$The installed package that carries this extension. Absent for a registered extension, which has no package.
500Operations invokable via POST /v1/extensions/{name}/invoke.
The HTTPS address this host calls.
The decision points this extension sits on.
The slots it occupies.
Where it sits in the ordered pipeline, lowest first.
The permission slugs granted ON this registration. An extension reaches every unmarked session in its home; a private one only where sessions:read-private is granted here.
What a registered supplier serves. Absent unless the extension occupies a supplier slot — and absent there too while that slot is CLAIMED AND UNSERVED. A supplier with nothing here offers nothing to any turn: the catalogue skips such a row exactly as it skips a disabled one, so a slot nobody has served yet is not selectable and not a provider anybody sees.
Whether this home is serving the tools this registration publishes RIGHT NOW — that is, whether a model in this home can call them. Present on every extension that occupies the tool-server slot and absent on every one that does not, because it is a fact about that claim and about nothing else.
It is false far more often than an owner expects, and that is the reason this field exists. The write that registers a tool server reaches the endpoint not at all, so the slot is stored CLAIMED AND UNSERVED and stays that way until a sweep has read the endpoint's tool listing; and a listing whose names collide with tools this home already serves is refused by the tool registry, which leaves the registration standing and publishing nothing.
It is the last answer this home RECORDED, never a guess made at read time, so it survives a restart: a home brought back up under a standing collision still says it is refusing those tools rather than reporting them unread.
Why this home is not serving that registration's tools, in this host's own words — never a sentence the far side wrote. Present exactly when servingTools is false, and absent when it is true, because a reason for something that is not the case would be the two fields disagreeing.
It can say: that no sweep of this home has read the listing yet (every claim starts here, and a host built without a registered-extension pool stays here); that the tool registry refused the listing because another source already owns one of those names, naming both claimants; that the endpoint could not be reached or would not answer; that the listing carried no tool this host can serve; or that the owner has the registration switched off.
The owner's switch. A disabled registration is still listed, and still says where it pointed, because a registry that hid one would answer "what reads our conversations" with less than the truth.
True when Lerian installed this on a home Lerian hosts, without the owner's act. It travels on every read because it is the notice standing where consent would otherwise be: a member can always tell which extensions are theirs and which are Lerian's.
The subject of the verified token that registered it. Absent on an operator install, where there is no person to name.

