Docsloth / developers
Self-hostStart quickstart

docsloth.dev

Publish components

The registry is open and federated: publish to the hosted marketplace, your own registry, a Git repository or a package registry. Installing from an external source never levies a fee.

From scaffold to published package

  1. Forge scaffolds a manifest and source; the manifest is validated against the SDK policy before it is written.
  2. Declare trust honestly: pure, interactive or connected. Connected components must describe their tools; the host grants capabilities per publication.
  3. Ship a prop schema and fixture so hosts can validate props and render a conformance fallback.
  4. Test behaviour and accessibility: keyboard operation, reduced motion and an axe pass are part of the checklist.
  5. Sign and pin: artifacts are addressed by digest; a mismatch blocks installation.

What the host will refuse

  • Install scripts of any kind on control-plane hosts.
  • Components that request undeclared network or execution permissions.
  • Manifests without a pinned digest, or with a digest that does not match the artifact.
  • Anything that tries to reach secrets: components receive capability endpoints, never credentials.

Actions

Actions

  • Create package

    The component SDK validates manifests and builds signed artifacts; scaffolding is manual in 1.0.0 because no forge command ships. No account or cost.

  • Run conformance

    Conformance helpers ship in @docsloth/test-kit; they run locally against your fixtures and props schema, not in a hosted service.

  • Submit

    No hosted registry submission is enabled in this build; publish to your own registry, Git repository or package source. The host refusal rules are listed below.