Published in openvibe-contracts v0.114.0 (docs/adr/ADR-013-mod-manifest.md), rendered as is.

ADR-013: Mod manifest, trust and sandbox/resource model

Status: Accepted 2026-09-23. Gates Wave 12 (mods) and Wave 21 Stage C (sandboxed user code). Amended 2026-09-24: signing and review are open owner decisions; mod monetization only through Billing; manifest 1.1.0 (read/write grants, billing hooks, dependencies).

Context and current evidence

OpenVibe.Games has an authoritative world with Network SSO but no mod platform. Source.OpenVibe.Games has its own scripting runtime. Nothing in the platform can install, grant, revoke or sandbox third-party code (D39).

Decision

Alternatives considered

Migration consequences

None today: no mods exist. Games adopts the manifest when it adds its first mod hook.

Rollback

Revoke the grants; the manifest schema stays.

Acceptance tests

Amendment 2026-09-24: open decisions, monetization and manifest 1.1.0

Roadmap §28.3 (m6 and "Mod signing and review") asks for three things this ADR left implicit.

Open owner decisions: package signing and review

Neither is decided. Both stay open decisions for the owner, and nothing may fill them with a silent default.

  1. Package signing. Who signs a mod release and with what key: the publisher, the platform at review time, or both. Which artifact the signature covers: the manifest, the pack or bundle, and the Media asset hashes. Where a runtime checks the signature. What an unsigned release may do.
  2. Review process. Who reviews, against which checklist, and what a review changes. It may raise the trust tier. It never grants anything, because tiers stay metadata. Also open: how a published review is withdrawn, and whether the ADR's tier names (unreviewed, reviewed, first-party) or the roadmap §15 vocabulary are final (requirement ledger D32).

Until the owner decides, installs stay as they are. Only staff install mods: Games POST /api/v1/mods is staff-only, with the approved capability subset given at install. No self-service publishing or install exists. Executable mods wait for Host Stage C in any case. The decision will be recorded as a new amendment here, before any non-staff install path ships.

Monetization only through Billing

A mod earns money only through Billing and marketplace primitives (ADR-012, ADR-025), never around them:

Manifest 1.1.0 (openvibe-contracts v0.34.0)

mods.mod-manifest@1 gains three optional fields, so every 1.0.0 manifest stays valid:

Games validates against a local copy of the 1.0.0 schema (apps/server/src/mods/manifestSchema.ts). It adopts 1.1.0 when it bumps its contracts pin.