Version and compare an extension contract
A declared version number is not enough to determine whether authority, channels, or exposed data have changed. The tooling therefore computes a fingerprint from the public contract that is actually declared.
Developer fingerprint V1
cd cli node src/index.js extension fingerprint ../plugins/acme_pay # sha256:...
The hash is computed over a canonical representation of the public contract derived from extension.yaml and the runtime: identity and platform compatibility, projected descriptor, configSchema, events, external objects, and event payload contracts. The package version number is preserved in the snapshot but is not part of the hashed content.
Snapshot and comparison
node src/index.js extension fingerprint ../plugins/acme_pay --write ./acme-pay.contract.json node src/index.js extension diff ../plugins/acme_pay --against ./acme-pay.contract.json
The diff returns the contract paths that changed. Any difference is marked review_relevant as a precaution; the command does not itself decide on certification or re-review.
Changes to classify
Adding a channel, broadening permissions api_in, adding contributions, changing schemas/configuration, or evolving an event contract are changes that must be reviewed before distribution. A future review engine may classify these diffs more precisely.
Current limits
The fingerprint covers the identities of contributions declared in extension.yaml, but not the complete contract of Nodes and Agent Tools. Also review their parameters, outputs, and behavior when assessing update compatibility.
Use preflight as a complement: fingerprint and contract validity answer two different questions.