Published in openvibe-contracts v0.127.0 (docs/adr/ADR-054-inventory-authority.md), rendered as is.

ADR-054: The OpenVibe inventory — one authority for items across the network

Status: Accepted 2026-10-09 (plan track T21, step 1), on the owner's direction of 2026-10-08. Builds on ADR-012 (money lives only in Billing), ADR-025 (nothing traded between people without a new ADR), ADR-029 (account merge), ADR-033 (account export and deletion), ADR-035 (each authority owns its PostgreSQL database) and ADR-048 (one authority per resource).

Context

> Owner, 2026-10-08: "improve and overhaul/remake the inventory system to be more like steam / csgo / etc style > community driven and modular through sdk / api type shit rather than our current inventory seen on openvibe.live for > name fx and particles and all that shit it should be a cross site network wide shared multi purpose modular system > with user profiles and shit".

What exists today is Live's cosmetics, and only Live can see them:

Decision

1. A new authority: OpenVibe.Inventory

2. The model

A new kind is a contract plus a renderer, never a new table.

3. Who can do what (capabilities, guarded with requireCapability)

| Capability | Who | What | |---|---|---| | inventory.item.read | public | a person's public inventory and equipped set, definitions, kinds | | inventory.item.list | the person, or a service acting for them | their own full inventory, including hidden items | | inventory.equip.manage | the person, or a service acting for them | equip and unequip their own instances | | inventory.item.grant | an issuer, for definitions it issued, and the grantors it names on a definition | grant an instance to a subject (idempotent per key) | | inventory.item.consume | an issuer, for definitions it issued | consume or revoke an instance | | inventory.definition.manage | an issuer, for its namespace | create, edit, submit, retire definitions | | inventory.definition.review | staff | publish or reject a submitted definition |

Apps act with grants from Services (ADR-048). A grant to an app names the definition namespace it may issue in.

Grantors (amendment, 2026-10-09). A definition may name grantors: other services or apps its issuer lets grant that one item. A grantor grants only: origin earned or granted, idempotent per its own key, within the supply cap, recorded in the ledger with the grantor as the actor. Defining, editing, consuming and revoking stay the issuer's, and the issuer sets and clears the list (PATCH /definitions/:id). This is how an item is earned on one site and issued by another: Live stays the issuer of its hats while OpenVibe.Quest gives some of them as quest rewards.

4. Events

The authority publishes these on OpenVibe.Events through its outbox:

A person's own item events have visibility subject, and public profile changes are public.

5. The money boundary

ADR-012 and ADR-025 hold until a later ADR changes them.

6. Community items (the Workshop)

The Workshop, v1 (amendment, 2026-10-09). Money stays out (§5); everything below is free.

7. Account data and merge

8. Live's cosmetics are the first kinds (convert, verify, delete)

  1. Convert:
  1. Verify: each person's unlocked set and equipped slots match, row for row, on both sides.
  2. Switch: Live reads through Inventory, behind a Live setting INVENTORY_AUTHORITY (live until the switch, then inventory). Its routes become calls to Inventory with Live's service token acting for the person.
  3. Delete: after the N-1 window, a contract migration drops user_cosmetics, user_equipped and user_equipped_tag. Live keeps the CSS and speech renderers.

Alternatives considered

Rollback

Acceptance tests