Version and compare an extension contract

A declared version number is not enough to determine whether authority, channels, or exposed data have changed. The tooling therefore computes a fingerprint from the public contract that is actually declared.

Developer fingerprint V1

Shell
cd cli
node src/index.js extension fingerprint ../plugins/acme_pay
# sha256:...

The hash is computed over a canonical representation of the public contract derived from extension.yaml and the runtime: identity and platform compatibility, projected descriptor, configSchema, events, external objects, and event payload contracts. The package version number is preserved in the snapshot but is not part of the hashed content.

Snapshot and comparison

Shell
node src/index.js extension fingerprint ../plugins/acme_pay --write ./acme-pay.contract.json

node src/index.js extension diff ../plugins/acme_pay --against ./acme-pay.contract.json

The diff returns the contract paths that changed. Any difference is marked review_relevant as a precaution; the command does not itself decide on certification or re-review.

Changes to classify

Adding a channel, broadening permissions api_in, adding contributions, changing schemas/configuration, or evolving an event contract are changes that must be reviewed before distribution. A future review engine may classify these diffs more precisely.

Current limits

The fingerprint covers the identities of contributions declared in extension.yaml, but not the complete contract of Nodes and Agent Tools. Also review their parameters, outputs, and behavior when assessing update compatibility.

Use preflight as a complement: fingerprint and contract validity answer two different questions.