{% raw %}
# WebSocket Protocol Index

Auto-generated by `scripts/gen-ws-namespace-index.sh` from `docs/websocket-protocol.md` — do not hand-edit. Regenerate after any change to that file: `bash scripts/gen-ws-namespace-index.sh`.

Compact map of every JSON-RPC method under "## Method reference": namespace, method, a one-line summary, and a deep link into the full [protocol reference](websocket-protocol.md) for params/returns/behavior. Load this file first; follow a link only for the method(s) you need.

**Not indexed, on purpose:** the separate "## Notification methods (server → client)" section (`host.event`, `voice.event`, `coder.event`, `coder.discuss.event`, `browser.signin_needed`/`resolved`) documents push-notification *payload shapes*, not additional namespaced RPC methods — read it directly in the full doc. Six headings documented **inside** "## Method reference" itself are excluded for the same reason — they are server-initiated pushes, not client-callable requests: `browser.view.event`, `models.pull_progress`, `models.upgrade_available`, `models.suggestion_available`, `runs.trace.event`, and `coder.session_changed` (documented a second time, briefly, in the separate Notification methods section above). The "a2a (in-core dispatcher)" subsection's 9-11 A2A v1.0 methods are also excluded: they're documented as a table of `PascalCase` / `slash/form` name pairs with no per-method heading to anchor to, and the source doc doesn't say which form is the literal wire `method` string.

**81 namespaces, 489 methods.**

## a2a (7)

- [`a2a.peers.add`](websocket-protocol.md#a2apeersadd-a2apeerslist-a2apeersremove) — Params { url: string, label?: string,...
- [`a2a.peers.list`](websocket-protocol.md#a2apeersadd-a2apeerslist-a2apeersremove) — Params {}. Returns { peers: PeerEntry[] }.
- [`a2a.peers.remove`](websocket-protocol.md#a2apeersadd-a2apeerslist-a2apeersremove) — Params { slug: string }.
- [`a2a.send`](websocket-protocol.md#a2asend) — Sends an A2A SendMessage request to a peer endpoint.
- [`a2a.start`](websocket-protocol.md#a2astart) — Errors if a server is already running, the bind...
- [`a2a.status`](websocket-protocol.md#a2astatus) — polling code doesn't have to distinguish "not...
- [`a2a.stop`](websocket-protocol.md#a2astop) — Errors if no server is running.

## a2ui (11)

- [`a2ui.action`](websocket-protocol.md#a2uiaction) — Called by the host renderer when the user activates...
- [`a2ui.apply`](websocket-protocol.md#a2uiapply) — Applies one direct A2UI v0.9.1 (or v0.9) message...
- [`a2ui.capabilities`](websocket-protocol.md#a2uicapabilities) — Reports the catalog/component set and server-side...
- [`a2ui.get`](websocket-protocol.md#a2uiget)
- [`a2ui.ingest`](websocket-protocol.md#a2uiingest) — Scans A2A-shaped data/artifact/task payloads for...
- [`a2ui.reap`](websocket-protocol.md#a2uireap) — Removes expired surfaces and their server-side...
- [`a2ui.render_report`](websocket-protocol.md#a2uirender_report)
- [`a2ui.surfaces`](websocket-protocol.md#a2uisurfaces)
- [`a2ui/replay`](websocket-protocol.md#a2uireplay) — Intended for late-joiners and reconnect: a client calls
- [`a2ui/subscribe`](websocket-protocol.md#a2uisubscribe) — Opt this WS connection into a2ui.event...
- [`a2ui/unsubscribe`](websocket-protocol.md#a2uiunsubscribe) — Idempotent.

## accounts (2)

- [`accounts.list`](websocket-protocol.md#accountslist) — OS-native account discovery.
- [`accounts.open`](websocket-protocol.md#accountsopen)

## admission (1)

- [`admission.status`](websocket-protocol.md#admissionstatus) — Read-only snapshot.

## agent (5)

- [`agent.browser.capture`](websocket-protocol.md#agentbrowserinput-agentbrowsercontrol-agentbrowsercapture-agentbrowserhost_connected-daemon-agent-reverse-calls) — params { enabled: boolean } → { ok: true }.
- [`agent.browser.control`](websocket-protocol.md#agentbrowserinput-agentbrowsercontrol-agentbrowsercapture-agentbrowserhost_connected-daemon-agent-reverse-calls) — params { action: "take_control" | "hand_back" |...
- [`agent.browser.host_connected`](websocket-protocol.md#agentbrowserinput-agentbrowsercontrol-agentbrowsercapture-agentbrowserhost_connected-daemon-agent-reverse-calls) — params { connected: boolean } → { ok: true }.
- [`agent.browser.input`](websocket-protocol.md#agentbrowserinput-agentbrowsercontrol-agentbrowsercapture-agentbrowserhost_connected-daemon-agent-reverse-calls) — params are one of { op: "navigate", url } · { op:...
- [`agent.chat`](websocket-protocol.md#agentchat-daemon-agent-reverse-call-agentchatevent) — For attached supervised agents, agents.chat...

## agent_permissions (10)

- [`agent_permissions.evaluate`](websocket-protocol.md#agent_permissions-per-agent-approval-policy-ws-only) — Params { agent_id, tier }.
- [`agent_permissions.evaluate_tool`](websocket-protocol.md#agent_permissions-per-agent-approval-policy-ws-only) — Host-management-only and capability-gated.
- [`agent_permissions.get`](websocket-protocol.md#agent_permissions-per-agent-approval-policy-ws-only) — Params {}. Returns the raw policy { default:...
- [`agent_permissions.list_grants`](websocket-protocol.md#agent_permissions-per-agent-approval-policy-ws-only) — Host-management-only.
- [`agent_permissions.reset`](websocket-protocol.md#agent_permissions-per-agent-approval-policy-ws-only) — Host-management-only.
- [`agent_permissions.reset_tool`](websocket-protocol.md#agent_permissions-per-agent-approval-policy-ws-only) — Host-management-only.
- [`agent_permissions.revoke_grant`](websocket-protocol.md#agent_permissions-per-agent-approval-policy-ws-only) — Host-management-only.
- [`agent_permissions.set`](websocket-protocol.md#agent_permissions-per-agent-approval-policy-ws-only) — Host-management-only.
- [`agent_permissions.set_default`](websocket-protocol.md#agent_permissions-per-agent-approval-policy-ws-only) — Host-management-only.
- [`agent_permissions.set_tool`](websocket-protocol.md#agent_permissions-per-agent-approval-policy-ws-only) — Host-management-only and capability-gated.

## agents (22)

- [`agents.chat`](websocket-protocol.md#agentschat) — Task scoping on authenticated A2A surfaces.
- [`agents.chat.approve`](websocket-protocol.md#agentschatapprove) — Authorization: the caller must be the host session...
- [`agents.chat.cancel`](websocket-protocol.md#agentschatcancel) — Best-effort cancellation.
- [`agents.detect_external`](websocket-protocol.md#agentsdetect_external) — same as agents.list_external but always...
- [`agents.health`](websocket-protocol.md#agentshealth) — Use after a system upgrade to surface broken specs...
- [`agents.health_external`](websocket-protocol.md#agentshealth_external) — not_executable is set by detection, not by an...
- [`agents.install`](websocket-protocol.md#agentsinstall) — Authorization: host-management authority.
- [`agents.invoke_external`](websocket-protocol.md#agentsinvoke_external) — Authorization: a host, and a client not bound to an...
- [`agents.list`](websocket-protocol.md#agentslist) — blocked_by_pid (car#732) is present only when the...
- [`agents.list_external`](websocket-protocol.md#agentslist_external) — execution (car#746) answers a different question...
- [`agents.message`](websocket-protocol.md#agentsmessage) — Authorization: the caller must be a bound agent or...
- [`agents.message.approve`](websocket-protocol.md#agentsmessageapprove) — Authorization: host-only, as above.
- [`agents.message.pending`](websocket-protocol.md#agentsmessagepending) — Authorization: host-only.
- [`agents.peers`](websocket-protocol.md#agentspeers) — Lists the peers visible to this caller.
- [`agents.register_basics`](websocket-protocol.md#agentsregister_basics) — Registers CAR's built-in agent utility tools on...
- [`agents.remove`](websocket-protocol.md#agentsremove) — Authorization: host-management authority.
- [`agents.restart`](websocket-protocol.md#agentsrestart) — Authorization: the same bound agent id or...
- [`agents.start`](websocket-protocol.md#agentsstart) — Authorization: the same bound agent id or...
- [`agents.stop`](websocket-protocol.md#agentsstop) — Authorization: the same bound agent id or...
- [`agents.tail_log`](websocket-protocol.md#agentstail_log) — Bounded read: agent logs are append-only and never...
- [`agents.upsert`](websocket-protocol.md#agentsupsert) — Authorization: host-management authority.
- [`agents.wait`](websocket-protocol.md#agentswait) — Blocks until a supervised agent reaches a target...

## assistant (2)

- [`assistant.identity.get`](websocket-protocol.md#assistantidentityget) — aliases is derived, not stored: the name and its...
- [`assistant.identity.set`](websocket-protocol.md#assistantidentityset) — Read-modify-write: every field is optional and...

## assistants (1)

- [`assistants.invoke`](websocket-protocol.md#assistantsinvoke) — Daemon-owned invocation of a built-in ready-to-use...

## automation (4)

- [`automation.run_applescript`](websocket-protocol.md#automationrun_applescript) — Wraps osascript -l <lang> - with the script piped...
- [`automation.run_powershell`](websocket-protocol.md#automationrun_powershell) — The Windows analog of run_applescript.
- [`automation.shortcuts.list`](websocket-protocol.md#automationshortcutslist) — Enumerates Shortcuts.app entries.
- [`automation.shortcuts.run`](websocket-protocol.md#automationshortcutsrun) — Invokes a Shortcut.

## bookmarks (1)

- [`bookmarks.list`](websocket-protocol.md#bookmarkslist)

## browser (21)

- [`browser.close`](websocket-protocol.md#browserclose)
- [`browser.producer.frame`](websocket-protocol.md#browserproducerpresentation-browserproducerframe-client-server-notifications-no-id) — browser.producer.presentation: { presentation:...
- [`browser.producer.presentation`](websocket-protocol.md#browserproducerpresentation-browserproducerframe-client-server-notifications-no-id) — browser.producer.presentation: { presentation:...
- [`browser.producer.register`](websocket-protocol.md#browserproducerregister) — Idempotent for the same connection.
- [`browser.run`](websocket-protocol.md#browserrun) — script accepts an inline JSON string or structured...
- [`browser.view.back`](websocket-protocol.md#the-input-methods)
- [`browser.view.click`](websocket-protocol.md#the-input-methods) — { x: number, y: number } — viewport pixels,...
- [`browser.view.forward`](websocket-protocol.md#the-input-methods)
- [`browser.view.hand_back`](websocket-protocol.md#browserviewtake_control-browserviewhand_back) — take_control records the calling connection as the...
- [`browser.view.keypress`](websocket-protocol.md#the-input-methods) — { key: string, modifiers?: ("alt" \| "control" \|...
- [`browser.view.navigate`](websocket-protocol.md#the-input-methods) — { url: string }
- [`browser.view.paste`](websocket-protocol.md#the-input-methods) — { text: string }
- [`browser.view.reload`](websocket-protocol.md#the-input-methods)
- [`browser.view.scroll`](websocket-protocol.md#the-input-methods) — { delta_y: integer }
- [`browser.view.subscribe`](websocket-protocol.md#browserviewsubscribe) — Atomicity. The presentation read and the subscriber...
- [`browser.view.tab_close`](websocket-protocol.md#the-input-methods) — { tab_id: string }
- [`browser.view.tab_open`](websocket-protocol.md#the-input-methods) — — (response adds tab_id: string)
- [`browser.view.tab_switch`](websocket-protocol.md#the-input-methods) — { tab_id: string }
- [`browser.view.take_control`](websocket-protocol.md#browserviewtake_control-browserviewhand_back) — take_control records the calling connection as the...
- [`browser.view.type`](websocket-protocol.md#the-input-methods) — { text: string }
- [`browser.view.unsubscribe`](websocket-protocol.md#browserviewunsubscribe) — WS-only — no FFI binding.

## builder (1)

- [`builder.build`](websocket-protocol.md#builderbuild) — Natural language → a runnable car-workflow manifest...

## calendar (5)

- [`calendar.create_event`](websocket-protocol.md#calendarcreate_event) — Approval: required by the default high-risk WS gate.
- [`calendar.delete_event`](websocket-protocol.md#calendardelete_event) — Approval: required by the default high-risk WS gate.
- [`calendar.events`](websocket-protocol.md#calendarevents) — { name?, email?, status?, role?, is_current_user }...
- [`calendar.list`](websocket-protocol.md#calendarlist)
- [`calendar.update_event`](websocket-protocol.md#calendarupdate_event) — Approval: required by the default high-risk WS gate.

## cascade (1)

- [`cascade.run`](websocket-protocol.md#cascaderun) — U-Mem Slice 5 live evolve loop (arXiv 2602.22406).

## coder (23)

- [`coder.approve_merge`](websocket-protocol.md#coderapprove_merge) — The second human gate, valid only in needs_approval.
- [`coder.cancel`](websocket-protocol.md#codercancel) — reason names a non-operator cause — a harness wall...
- [`coder.confirm_contract`](websocket-protocol.md#coderconfirm_contract) — The first human gate.
- [`coder.discuss.close`](websocket-protocol.md#coderdiscuss) — Params { discussion_id }.
- [`coder.discuss.list`](websocket-protocol.md#coderdiscuss) — Params {}. Returns
- [`coder.discuss.promote`](websocket-protocol.md#coderdiscuss) — Params { discussion_id }.
- [`coder.discuss.send`](websocket-protocol.md#coderdiscuss) — Params { discussion_id, text }.
- [`coder.discuss.start`](websocket-protocol.md#coderdiscuss) — Params { repo: string, resume_id?: string, model?:...
- [`coder.discuss.subscribe`](websocket-protocol.md#coderdiscuss) — Params
- [`coder.discuss.unsubscribe`](websocket-protocol.md#coderdiscuss) — Params
- [`coder.get`](websocket-protocol.md#coderget) — event_cursor reserves the next event sequence at...
- [`coder.list`](websocket-protocol.md#coderlist) — live sessions plus persisted snapshots from prior...
- [`coder.projects.create`](websocket-protocol.md#managed-projects-coderprojects) — Params { name: string, kind?: "app"|"agent",...
- [`coder.projects.get`](websocket-protocol.md#managed-projects-coderprojects) — Params { slug: string }.
- [`coder.projects.list`](websocket-protocol.md#managed-projects-coderprojects) — Params {}. Returns { projects: [CoderProject] },...
- [`coder.refresh_review`](websocket-protocol.md#coderrefresh_review) — Available only for a stopped native task with a...
- [`coder.respond`](websocket-protocol.md#coderrespond) — Answers a mid-session user_input_requested event.
- [`coder.revise_contract`](websocket-protocol.md#coderrevise_contract) — Redrafts a proposed contract from the operator's...
- [`coder.start`](websocket-protocol.md#coderstart) — Provisions the worktree, resolves the engine (auto...
- [`coder.subscribe`](websocket-protocol.md#codersubscribe-coderunsubscribe) — reattach_headless_start: true reclaims a detached...
- [`coder.unsubscribe`](websocket-protocol.md#codersubscribe-coderunsubscribe) — reattach_headless_start: true reclaims a detached...
- [`coder.unwatch`](websocket-protocol.md#coderwatch-coderunwatch) — The board's one subscription.
- [`coder.watch`](websocket-protocol.md#coderwatch-coderunwatch) — The board's one subscription.

## concierge (12)

- [`concierge.actions`](websocket-protocol.md#conciergeactions) — the auditable log of
- [`concierge.apply`](websocket-protocol.md#conciergeapply) — Closed-loop "set it up" (Phase D3): acquires the...
- [`concierge.ask`](websocket-protocol.md#conciergeask) — Conversational concierge (Phase F1/F2).
- [`concierge.clear_default`](websocket-protocol.md#conciergeclear_default)
- [`concierge.defaults`](websocket-protocol.md#conciergedefaults) — Per-lane (optionally project-scoped) default models...
- [`concierge.dismiss`](websocket-protocol.md#conciergedismiss) — Records a *labeled* dismissal: permanent reasons...
- [`concierge.maintain`](websocket-protocol.md#conciergemaintain) — Runs one maintenance pass now, the same pass the...
- [`concierge.portfolio`](websocket-protocol.md#conciergeportfolio) — Assesses every installed local model, reads only,...
- [`concierge.refresh_catalog`](websocket-protocol.md#conciergerefresh_catalog) — Fetches the signed model catalog —...
- [`concierge.rollback`](websocket-protocol.md#conciergerollback) — Reverts the lane default to its value before the...
- [`concierge.set_default`](websocket-protocol.md#conciergeset_default) — A project entry overrides the global (project...
- [`concierge.status`](websocket-protocol.md#conciergestatus) — The pull-not-push surface CarHost's Model Health...

## connectors (10)

- [`connectors.add`](websocket-protocol.md#connectorsadd) — For unauthenticated or static-token servers.
- [`connectors.add_stdio`](websocket-protocol.md#connectorsadd_stdio) — Registers a local MCP server launched as a...
- [`connectors.authenticate`](websocket-protocol.md#connectorsauthenticate) — Begins an OAuth 2.1 flow: runs Protected Resource +...
- [`connectors.complete_authentication`](websocket-protocol.md#connectorscomplete_authentication) — Exchanges the authorization code for tokens...
- [`connectors.disable_tools`](websocket-protocol.md#connectorsdisable_tools) — Drops the named tools' routes and unregisters their...
- [`connectors.enable_tools`](websocket-protocol.md#connectorsenable_tools) — Routes the named tools and registers their schemas...
- [`connectors.list`](websocket-protocol.md#connectorslist)
- [`connectors.refresh`](websocket-protocol.md#connectorsrefresh) — re-runs tools/list and re-registers any
- [`connectors.remove`](websocket-protocol.md#connectorsremove) — Disconnects, drops routes, deletes keychain...
- [`connectors.tools`](websocket-protocol.md#connectorstools) — { name, canonical, description, enabled: bool }

## contacts (2)

- [`contacts.containers`](websocket-protocol.md#contactscontainers)
- [`contacts.find`](websocket-protocol.md#contactsfind)

## declagents (10)

- [`declagents.get`](websocket-protocol.md#declagents) — Params { id: string }.
- [`declagents.invoke`](websocket-protocol.md#declagents) — Params { id: string, input: string }.
- [`declagents.list`](websocket-protocol.md#declagents) — Params {}. Returns { agents: [{ id, name,...
- [`declagents.remove`](websocket-protocol.md#declagents) — Params { id: string }.
- [`declagents.revert`](websocket-protocol.md#declagents) — Params { id: string }.
- [`declagents.route`](websocket-protocol.md#declagents) — Params { need: string, invoke?: bool, from?:...
- [`declagents.route_split`](websocket-protocol.md#declagents) — Params { need: string, invoke?: bool,...
- [`declagents.routing_stats`](websocket-protocol.md#declagents) — Params {}. Returns { agents: { <id>: { successes,...
- [`declagents.run_scenarios`](websocket-protocol.md#declagents) — Params { id: string }.
- [`declagents.set_enabled`](websocket-protocol.md#declagents) — Params { id: string, enabled: bool }.

## discovery (3)

- [`discovery.report`](websocket-protocol.md#declagents) — Params { identifier: string, outcome:...
- [`discovery.resolve`](websocket-protocol.md#declagents) — Params { need: string, limit?: number }.
- [`discovery.route_compose`](websocket-protocol.md#declagents) — Params { need: string, max_subtasks?: number,...

## events (9)

- [`events.chain.enable`](websocket-protocol.md#eventschainenable) — Turns on tamper-evident hash chaining for the...
- [`events.chain.verify`](websocket-protocol.md#eventschainverify) — Detects interior edits, deletions, and reorderings...
- [`events.clear`](websocket-protocol.md#eventsclear) — Destructive and unconditional — drops the entire...
- [`events.cost_by_agent`](websocket-protocol.md#eventscost_by_agent)
- [`events.count`](websocket-protocol.md#eventscount) — per-session event log size
- [`events.query`](websocket-protocol.md#eventsquery) — Runtime proposal-executor tool provenance is...
- [`events.retention`](websocket-protocol.md#eventsretention) — Bounds the log by size and age so it can't grow...
- [`events.stats`](websocket-protocol.md#eventsstats) — current event and span counts for the session log.
- [`events.truncate`](websocket-protocol.md#eventstruncate) — Keeps the last N of each and drops the rest.

## evolution (2)

- [`evolution.plan`](websocket-protocol.md#evolutionplan) — Self-evolution governor live host surface (arXiv...
- [`evolution.run`](websocket-protocol.md#evolutionrun) — The governor's real executor (arXiv 2507.21046 —...

## feedback (4)

- [`feedback.compose_preview`](websocket-protocol.md#feedbackcompose_preview) — The consent preview: assembles the exact...
- [`feedback.list`](websocket-protocol.md#feedbacklist) — the newest limit merged local/server rows, kept in...
- [`feedback.status`](websocket-protocol.md#feedbackstatus) — filtered to the one entry when submission_id is...
- [`feedback.submit`](websocket-protocol.md#feedbacksubmit) — Composes the same bundle and durably enqueues it in...

## files (1)

- [`files.locations`](websocket-protocol.md#fileslocations)

## fleet (4)

- [`fleet.composite`](websocket-protocol.md#fleetcomposite) — FFI: fleetComposite(includeRemote?, timeoutMs?)...
- [`fleet.inventory`](websocket-protocol.md#fleetinventory) — This is the same report peers receive over A2A,...
- [`fleet.worker.get`](websocket-protocol.md#fleetworkerget) — config is what an operator set...
- [`fleet.worker.set`](websocket-protocol.md#fleetworkerset) — Operator-only, and a real grant.

## foreman (2)

- [`foreman.plan`](websocket-protocol.md#foremanplan) — FFI: foremanPlan(goal, repo?, maxAttempts?) (Node)...
- [`foreman.run`](websocket-protocol.md#foremanrun) — FFI: foremanRun(goal, repo?, adapter?,...

## goal (4)

- [`goal.clear`](websocket-protocol.md#goalclear)
- [`goal.set`](websocket-protocol.md#goalset)
- [`goal.status`](websocket-protocol.md#goalstatus)
- [`goal.suggest`](websocket-protocol.md#goalsuggest)

## heal (2)

- [`heal.run`](websocket-protocol.md#healrun) — One sweep now instead of waiting for the cadence:...
- [`heal.status`](websocket-protocol.md#healstatus) — heal.toml is re-read on every call and on every...

## health (4)

- [`health.activity`](websocket-protocol.md#healthactivity) — note date-only format
- [`health.sleep`](websocket-protocol.md#healthsleep)
- [`health.status`](websocket-protocol.md#healthstatus)
- [`health.workouts`](websocket-protocol.md#healthworkouts)

## host (13)

- [`host.agents`](websocket-protocol.md#hostagents) — agents explicitly registered into host state...
- [`host.approvals`](websocket-protocol.md#hostapprovals)
- [`host.devices`](websocket-protocol.md#hostdevices) — Parslee Core exposes this same read-only roster...
- [`host.events`](websocket-protocol.md#hostevents)
- [`host.notify`](websocket-protocol.md#hostnotify) — Native hosts may honor payload.target_device_id to...
- [`host.register_agent`](websocket-protocol.md#hostregister_agent)
- [`host.register_device`](websocket-protocol.md#hostregister_device) — Ownership follows the registering WebSocket session.
- [`host.request_approval`](websocket-protocol.md#hostrequest_approval) — action is required: the one-line summary every...
- [`host.resolve_approval`](websocket-protocol.md#hostresolve_approval) — resolution is the verb, matched against the row's...
- [`host.set_status`](websocket-protocol.md#hostset_status) — Broadcasts an agent.status_changed event to...
- [`host.subscribe`](websocket-protocol.md#hostsubscribe) — Registers the connection to receive host.event...
- [`host.unregister_agent`](websocket-protocol.md#hostunregister_agent)
- [`host.update_device`](websocket-protocol.md#hostupdate_device) — Broadcasts a device.updated host event to subscribers.

## image (1)

- [`image.generate`](websocket-protocol.md#imagegenerate) — The CLI's car image … routes through this method...

## infer (2)

- [`infer.cancel`](websocket-protocol.md#infercancel) — Requires the optional infer.cancel.v1 capability to...
- [`infer.deadline`](websocket-protocol.md#inferdeadline) — Requires the optional infer.deadline.v1 capability...

## inference (4)

- [`inference.register_runner`](websocket-protocol.md#inferenceregister_runner) — Marks this WebSocket session as the inference...
- [`inference.runner.complete`](websocket-protocol.md#inferencerunnercomplete) — Called by the runner host once the upstream call...
- [`inference.runner.event`](websocket-protocol.md#inferencerunnerevent) — Optional. A runner that has nothing to stream may...
- [`inference.runner.fail`](websocket-protocol.md#inferencerunnerfail) — Called by the runner host on upstream failure (HTTP...

## keychain (1)

- [`keychain.status`](websocket-protocol.md#keychainstatus)

## lattice (33)

- [`lattice.claim`](websocket-protocol.md#latticeclaim) — Exclusive: the holder check and the insert happen...
- [`lattice.claims`](websocket-protocol.md#latticeclaims)
- [`lattice.connect.accept`](websocket-protocol.md#latticeconnectaccept) — Accepts an invite with this side's own share list.
- [`lattice.connect.confirm`](websocket-protocol.md#latticeconnectconfirm) — The inviter confirms the CAR that accepted.
- [`lattice.connect.inspect`](websocket-protocol.md#latticeconnectinspect) — What an invite asks for, before accepting it.
- [`lattice.connect.invite`](websocket-protocol.md#latticeconnectinvite) — Authorization: host-only for this and every...
- [`lattice.connect.share`](websocket-protocol.md#latticeconnectshare) — Replaces what THIS side shares on an active...
- [`lattice.connections`](websocket-protocol.md#latticeconnections) — Every connection, newest first, without secrets.
- [`lattice.directory`](websocket-protocol.md#latticedirectory) — Colleagues (this account excluded) and their CARs,...
- [`lattice.disconnect`](websocket-protocol.md#latticedisconnect) — Ends a connection on this side immediately — the...
- [`lattice.find`](websocket-protocol.md#latticefind) — Matching is lexical and deterministic — it needs no...
- [`lattice.join`](websocket-protocol.md#latticejoin) — Calling again replaces the profile — that is how a...
- [`lattice.knock`](websocket-protocol.md#latticeknock) — With org, the knock presents this CAR's Parslee...
- [`lattice.knock.accept`](websocket-protocol.md#latticeknockaccept) — Accepts an incoming knock with this owner's label...
- [`lattice.knock.block`](websocket-protocol.md#latticeknockblock) — mode is block (refused at the door; its pending...
- [`lattice.knock.decline`](websocket-protocol.md#latticeknockdecline) — Drops the knock and tells the knocking CAR (best...
- [`lattice.knock.settings`](websocket-protocol.md#latticeknocksettings) — Reads, or sets, whether this CAR is discoverable on...
- [`lattice.knock.withdraw`](websocket-protocol.md#latticeknockwithdraw) — Withdraws a knock this side sent: the row and its...
- [`lattice.knocks`](websocket-protocol.md#latticeknocks) — the certificate's account, never a name the knocker...
- [`lattice.leave`](websocket-protocol.md#latticeleave) — Without params, drops the caller's profile and...
- [`lattice.nodes`](websocket-protocol.md#latticenodes) — Lists live nodes — an agent profile whose...
- [`lattice.org.attest`](websocket-protocol.md#latticeorgattest) — Granters only — an operator whose login-derived...
- [`lattice.org.policy`](websocket-protocol.md#latticeorgpolicy) — Granters only. Publishes the org's Lattice policy,...
- [`lattice.org.revoke`](websocket-protocol.md#latticeorgrevoke) — Granters only. Voids every attestation of account...
- [`lattice.org.rule.add`](websocket-protocol.md#latticeorgruleadd) — Accepts, in advance, offers from attested...
- [`lattice.org.rule.remove`](websocket-protocol.md#latticeorgruleremove) — Withdraws a rule.
- [`lattice.org.rules`](websocket-protocol.md#latticeorgrules) — this operator's standing auto-accept rules for the org.
- [`lattice.org.status`](websocket-protocol.md#latticeorgstatus) — Whether org connections are on, and this CAR's...
- [`lattice.relay.probe`](websocket-protocol.md#latticerelayprobe) — Host-only. A developer check of the Parslee relay...
- [`lattice.release`](websocket-protocol.md#latticerelease) — Releases a claim the caller holds.
- [`lattice.requests`](websocket-protocol.md#latticerequests) — Authorization: host-only, with no exception for a...
- [`lattice.respond`](websocket-protocol.md#latticerespond) — Authorization: host-only, as above — an answer here...
- [`lattice.wait`](websocket-protocol.md#latticewait) — Blocks until a reply to that message arrives — a...

## lease (4)

- [`lease.acquire`](websocket-protocol.md#leaseacquire) — CAS-acquire the lease; grants iff unheld or...
- [`lease.release`](websocket-protocol.md#leaserelease) — Clean handoff — the next acquire grants immediately...
- [`lease.renew`](websocket-protocol.md#leaserenew) — Heartbeat: extend expires_at_ms without bumping the...
- [`lease.status`](websocket-protocol.md#leasestatus) — The linearizable read of the current lease (the...

## mail (6)

- [`mail.accounts`](websocket-protocol.md#mailaccounts) — Access: requires the daemon auth token when daemon...
- [`mail.inbox`](websocket-protocol.md#mailinbox) — Access: requires the daemon auth token when daemon...
- [`mail.mailboxes`](websocket-protocol.md#mailmailboxes) — Access: requires the daemon auth token when daemon...
- [`mail.message_body`](websocket-protocol.md#mailmessage_body) — Access: requires the daemon auth token when daemon...
- [`mail.messages`](websocket-protocol.md#mailmessages) — Access: requires the daemon auth token when daemon...
- [`mail.send`](websocket-protocol.md#mailsend) — Access: this is a mutation, not a read.

## meeting (4)

- [`meeting.get`](websocket-protocol.md#meetingget)
- [`meeting.list`](websocket-protocol.md#meetinglist) — defaults to current working directory
- [`meeting.start`](websocket-protocol.md#meetingstart) — Pushes voice.event notifications back to the client.
- [`meeting.stop`](websocket-protocol.md#meetingstop)

## memory (19)

- [`memory.add_fact`](websocket-protocol.md#memoryadd_fact) — kind: "constraint" sets the constraint flag.
- [`memory.admission_table`](websocket-protocol.md#memoryadmission_table) — Reads back the installed rules.
- [`memory.build_context`](websocket-protocol.md#memorybuild_context) — When model_context_window is provided, sizes the...
- [`memory.build_context_fast`](websocket-protocol.md#memorybuild_context_fast) — ContextMode::Fast.
- [`memory.consolidate`](websocket-protocol.md#memoryconsolidate) — operates on this client's per-session memgine.
- [`memory.delete`](websocket-protocol.md#memorydelete) — Removes a stale proactive memory entry by fact id.
- [`memory.evaluate`](websocket-protocol.md#memoryevaluate) — Offline calibration hook for proactive memory.
- [`memory.fact_count`](websocket-protocol.md#memoryfact_count) — valid_fact_count() of the session's memgine.
- [`memory.intervene`](websocket-protocol.md#memoryintervene) — Proactive memory hook for long-horizon runs.
- [`memory.load`](websocket-protocol.md#memoryload) — Replaces the session's memgine with the facts at path.
- [`memory.maintain`](websocket-protocol.md#memorymaintain) — Runs Phase 1 of proactive memory over the recent...
- [`memory.persist`](websocket-protocol.md#memorypersist) — Writes the session's memgine to a JSON file at path...
- [`memory.query`](websocket-protocol.md#memoryquery) — Personalized PageRank retrieval over the memory graph.
- [`memory.save_knowledge`](websocket-protocol.md#memorysave_knowledge) — Saves durable execution-state knowledge such as...
- [`memory.save_procedural`](websocket-protocol.md#memorysave_procedural) — Saves durable procedural evidence such as failed...
- [`memory.set_admission_table`](websocket-protocol.md#memoryset_admission_table) — Installs or clears the durable-state admission...
- [`memory.update_status`](websocket-protocol.md#memoryupdate_status) — Updates the proactive memory agent's private...
- [`memory.utility_get`](websocket-protocol.md#memoryutility_get) — the live engine's
- [`memory.utility_set`](websocket-protocol.md#memoryutility_set) — Runtime override of utility-aware fact retrieval on...

## messages (4)

- [`messages.chats`](websocket-protocol.md#messageschats)
- [`messages.read`](websocket-protocol.md#messagesread) — Access: requires the daemon auth token when daemon...
- [`messages.send`](websocket-protocol.md#messagessend)
- [`messages.services`](websocket-protocol.md#messagesservices)

## messaging (6)

- [`messaging.config.get`](websocket-protocol.md#messagingconfigget) — Rejected (-32603) for a non-host caller when a host...
- [`messaging.config.set`](websocket-protocol.md#messagingconfigset) — Slack token provisioning (channel: "slack" only):...
- [`messaging.pairing.start`](websocket-protocol.md#messagingpairingstart) — { pairing_code: string, config: MessagingConfigView }.
- [`messaging.pairing.status`](websocket-protocol.md#messagingpairingstatus) — { pairing_active: boolean, pairing_code?: string }...
- [`messaging.status`](websocket-protocol.md#messagingstatus) — { channel: "imessage" | "slack", enabled: boolean,...
- [`messaging.test_send`](websocket-protocol.md#messagingtest_send) — { ok: boolean, error?: string }.

## metrics (2)

- [`metrics.alerts`](websocket-protocol.md#metricsalerts) — The max_cost_usd budget is checked against the...
- [`metrics.summary`](websocket-protocol.md#metricssummary) — total_events, actions_succeeded /

## mobile (1)

- [`mobile.runtime`](websocket-protocol.md#mobileruntime) — Returns the internal runtime payload Parslee can...

## models (28)

- [`models.adopt`](websocket-protocol.md#modelsadopt)
- [`models.catalog_snapshot`](websocket-protocol.md#modelscatalog_snapshot) — Requires the models.catalog-identity.v1 capability...
- [`models.check_concierge`](websocket-protocol.md#modelscheck_concierge)
- [`models.check_upgrade_nudge`](websocket-protocol.md#modelscheck_upgrade_nudge) — { auto_apply: [UpgradeFinding], nudge?: { finding,...
- [`models.detect_upgrades`](websocket-protocol.md#modelsdetect_upgrades) — Combines curated rules, CAR's own benchmark, and...
- [`models.dismiss_suggestion`](websocket-protocol.md#modelsdismiss_suggestion) — Records that the user waved away a concierge...
- [`models.dismiss_upgrade`](websocket-protocol.md#modelsdismiss_upgrade) — Records that the user waved away a nudge so it...
- [`models.install`](websocket-protocol.md#modelsinstall) — Host-management only.
- [`models.list`](websocket-protocol.md#modelslist) — [ { name, hf_repo, hf_filename, tokenizer_repo,...
- [`models.list_unified`](websocket-protocol.md#modelslist_unified) — cost is the model's declared price structure: {...
- [`models.preflight`](websocket-protocol.md#modelspreflight)
- [`models.pull`](websocket-protocol.md#modelspull) — Host-management only.
- [`models.recommend`](websocket-protocol.md#modelsrecommend) — Ranks registry models for this machine + intent...
- [`models.register`](websocket-protocol.md#modelsregister) — Persists the supplied ModelSchema to models.json...
- [`models.remove`](websocket-protocol.md#modelsremove) — Requires a collision-checked receipt, serializes...
- [`models.resource_policy.get`](websocket-protocol.md#modelsresource_policyget) — Everyday evaluates to a 40% host-memory admission...
- [`models.resource_policy.set`](websocket-protocol.md#modelsresource_policyset) — Saving here is an explicit choice: it clears the...
- [`models.retire`](websocket-protocol.md#modelsretire) — Deletes what is CAR's of a local model and leaves...
- [`models.route`](websocket-protocol.md#modelsroute)
- [`models.route_provenance`](websocket-protocol.md#modelsroute_provenance) — Initialization requirement: the model registry must...
- [`models.search`](websocket-protocol.md#modelssearch) — Searchable registry view for host UIs and...
- [`models.setup_plan`](websocket-protocol.md#modelssetup_plan) — a host-actionable onboarding plan.
- [`models.stats`](websocket-protocol.md#modelsstats)
- [`models.storage_roots`](websocket-protocol.md#modelsstorage_roots) — HF_HUB_CACHE, then HUGGINGFACE_HUB_CACHE, then...
- [`models.unregister`](websocket-protocol.md#modelsunregister) — Symmetric counterpart to models.register.
- [`models.update_prefs_get`](websocket-protocol.md#modelsupdate_prefs_get) — { channel: "stable"|"latest", policy:...
- [`models.update_prefs_set`](websocket-protocol.md#modelsupdate_prefs_set) — A team-shared project .car/update-prefs.json...
- [`models.upgrades`](websocket-protocol.md#modelsupgrades) — Curated installed-model upgrade hints from the...

## multi (7)

- [`multi.map_reduce`](websocket-protocol.md#multimap_reduce)
- [`multi.pipeline`](websocket-protocol.md#multipipeline)
- [`multi.subtask`](websocket-protocol.md#multisubtask) — Runs the main agent with a spawn_subtask tool enabled.
- [`multi.supervisor`](websocket-protocol.md#multisupervisor)
- [`multi.swarm`](websocket-protocol.md#multiswarm)
- [`multi.tournament`](websocket-protocol.md#multitournament) — Each competitor produces one candidate answer to...
- [`multi.vote`](websocket-protocol.md#multivote)

## multiplayer (7)

- [`multiplayer.abandon`](websocket-protocol.md#multiplayerabandon) — Retires an item — for example when its locked...
- [`multiplayer.get`](websocket-protocol.md#multiplayerget) — the full record.
- [`multiplayer.list`](websocket-protocol.md#multiplayerlist) — eligible is null when signed out; ready_to_merge is...
- [`multiplayer.merge_check`](websocket-protocol.md#multiplayermerge_check) — push: true also pushes car/mp/<id>-final to the...
- [`multiplayer.publish`](websocket-protocol.md#multiplayerpublish) — The session must be finished: merged or reported...
- [`multiplayer.start_stage`](websocket-protocol.md#multiplayerstart_stage) — Fetches the item and refuses when the caller...
- [`multiplayer.submit_stage`](websocket-protocol.md#multiplayersubmit_stage) — For a stage done outside CAR — a developer's own...

## nlp (3)

- [`nlp.extract_entities`](websocket-protocol.md#nlpidentify_language-nlptokenize-nlpextract_entities) — backend is "apple" (macOS NaturalLanguage) or...
- [`nlp.identify_language`](websocket-protocol.md#nlpidentify_language-nlptokenize-nlpextract_entities) — backend is "apple" (macOS NaturalLanguage) or...
- [`nlp.tokenize`](websocket-protocol.md#nlpidentify_language-nlptokenize-nlpextract_entities) — backend is "apple" (macOS NaturalLanguage) or...

## notes (2)

- [`notes.accounts`](websocket-protocol.md#notesaccounts)
- [`notes.find`](websocket-protocol.md#notesfind)

## notifications (1)

- [`notifications.local`](websocket-protocol.md#notificationslocal) — Sends a user-visible local notification through the...

## outcomes (2)

- [`outcomes.resolve_pending`](websocket-protocol.md#outcomesresolve_pending) — Symmetric to the in-process...
- [`outcomes.scoreboard`](websocket-protocol.md#outcomesscoreboard) — usd_per_success (priced spend ÷ successes) is the...

## peers (2)

- [`peers.cert_conflict_clear`](websocket-protocol.md#peerscert_conflict_clear) — Host-only. The owner resolved an...
- [`peers.cert_status`](websocket-protocol.md#peerscert_status) — Host-only. This CAR's device certificates and what...

## permission (7)

- [`permission.approve`](websocket-protocol.md#permission-the-permission-tier-safety-governor-survey-343-525) — Params { fingerprint, required_tier, reason?, evidence?
- [`permission.classify`](websocket-protocol.md#permission-the-permission-tier-safety-governor-survey-343-525) — Params { proposal: ActionProposal }.
- [`permission.evaluate`](websocket-protocol.md#permission-the-permission-tier-safety-governor-survey-343-525) — Params { proposal, skill?
- [`permission.get_tier`](websocket-protocol.md#permission-the-permission-tier-safety-governor-survey-343-525) — Returns { granted_tier }.
- [`permission.pending`](websocket-protocol.md#permission-the-permission-tier-safety-governor-survey-343-525) — Params { proposal, skill?
- [`permission.reject`](websocket-protocol.md#permission-the-permission-tier-safety-governor-survey-343-525) — Params { fingerprint, required_tier, reason?, evidence?
- [`permission.set_tier`](websocket-protocol.md#permission-the-permission-tier-safety-governor-survey-343-525) — Params { tier:...

## permissions (4)

- [`permissions.domains`](websocket-protocol.md#permissionsdomains) — all known permission domain names
- [`permissions.explain`](websocket-protocol.md#permissionsexplain)
- [`permissions.request`](websocket-protocol.md#permissionsrequest)
- [`permissions.status`](websocket-protocol.md#permissionsstatus)

## photos (1)

- [`photos.albums`](websocket-protocol.md#photosalbums)

## policy (4)

- [`policy.list`](websocket-protocol.md#policylist) — What is currently in force, in registration order.
- [`policy.register`](websocket-protocol.md#policyregister) — Register a single policy on this WebSocket...
- [`policy.register`](websocket-protocol.md#policyregister-1) — Mirrors session.init's policy slot for callers that...
- [`policy.unregister`](websocket-protocol.md#policyunregister) — Remove every policy registered under name.

## proposal (1)

- [`proposal.submit`](websocket-protocol.md#proposalsubmit) — Triggers tools.execute callbacks to the client for...

## registry (5)

- [`registry.heartbeat`](websocket-protocol.md#registryheartbeat) — Recommended cadence: every 20s.
- [`registry.list`](websocket-protocol.md#registrylist) — sorted by name. Corrupt JSON files in the registry...
- [`registry.reap`](websocket-protocol.md#registryreap) — Recommended cadence: every 30s from the menubar...
- [`registry.register`](websocket-protocol.md#registryregister) — Atomic write — concurrent readers never see a...
- [`registry.unregister`](websocket-protocol.md#registryunregister) — Idempotent.

## reminders (2)

- [`reminders.items`](websocket-protocol.md#remindersitems)
- [`reminders.lists`](websocket-protocol.md#reminderslists)

## replan (1)

- [`replan.set_config`](websocket-protocol.md#replanset_config) — Configures the per-session replan loop.

## runs (10)

- [`runs.cancel`](websocket-protocol.md#runscancel-runscancelv1) — The connection must negotiate runs.cancel.v1 and...
- [`runs.complete`](websocket-protocol.md#runscomplete) — Records a terminal RunEnded record carrying the...
- [`runs.get_trace`](websocket-protocol.md#runsget_trace) — A timeout / Incomplete run is not an error: its...
- [`runs.list`](websocket-protocol.md#runslist) — Reads the disk store (~/.car/runs/{agent_id}/), not...
- [`runs.record_model_turn`](websocket-protocol.md#runsrecord_model_turn) — The daemon stamps the model turn's zero-based index...
- [`runs.record_turns`](websocket-protocol.md#runsrecord_turns) — Validation errors (a JSON-RPC error frame, not a...
- [`runs.resume`](websocket-protocol.md#runsresume-runsresumev1) — The connection must negotiate runs.resume.v1 and...
- [`runs.start`](websocket-protocol.md#runsstart) — The daemon mints the run_id (or adopts the...
- [`runs.subscribe`](websocket-protocol.md#runssubscribe) — Atomicity (R7). The snapshot read and the...
- [`runs.unsubscribe`](websocket-protocol.md#runsunsubscribe) — removed is true when a

## schedule (1)

- [`schedule.suggest`](websocket-protocol.md#schedulesuggest) — Deterministic and inference-free.

## scheduler (8)

- [`scheduler.create`](websocket-protocol.md#schedulercreate) — just constructs the task definition)
- [`scheduler.os_install`](websocket-protocol.md#durable-os-level-scheduling-scheduleros_) — Params: same as os_render.
- [`scheduler.os_list`](websocket-protocol.md#durable-os-level-scheduling-scheduleros_) — Params: none. Returns: a JSON array of installed...
- [`scheduler.os_reconcile`](websocket-protocol.md#durable-os-level-scheduling-scheduleros_) — Params: none. Returns: { removed: string[], kept:...
- [`scheduler.os_render`](websocket-protocol.md#durable-os-level-scheduling-scheduleros_) — Params: { task: object, program: string, args?:...
- [`scheduler.os_uninstall`](websocket-protocol.md#durable-os-level-scheduling-scheduleros_) — Params: { label: string } (full label or bare task id).
- [`scheduler.run`](websocket-protocol.md#schedulerrun) — Stateful dedup: the daemon seeds the posted task...
- [`scheduler.run_loop`](websocket-protocol.md#schedulerrun_loop) — Stateful dedup: same prior-history seeding and...

## secret (6)

- [`secret.available`](websocket-protocol.md#secretavailable) — whether the OS keychain is reachable
- [`secret.delete`](websocket-protocol.md#secretdelete)
- [`secret.get`](websocket-protocol.md#secretget) — A connection authenticated as a supervised agent is...
- [`secret.list`](websocket-protocol.md#secretlist) — Lists the names of secrets stored through the...
- [`secret.put`](websocket-protocol.md#secretput) — Uses the OS keychain (Keychain on macOS, Credential...
- [`secret.status`](websocket-protocol.md#secretstatus)

## selfheal (5)

- [`selfheal.detections`](websocket-protocol.md#selfhealdetections) — FFI: selfhealDetections(queryJson?) /...
- [`selfheal.dismiss`](websocket-protocol.md#selfhealdismiss) — Appends a dismissal marker; it never...
- [`selfheal.fix`](websocket-protocol.md#selfhealfix) — Starts one explicit bounded round even when...
- [`selfheal.run`](websocket-protocol.md#selfhealrun) — Runs the same path as the cadence.
- [`selfheal.status`](websocket-protocol.md#selfhealstatus) — route is "local" only when the tick validates a...

## server (1)

- [`server.schema`](websocket-protocol.md#serverschema) — The release version is reported here, not inside...

## session (6)

- [`session.bindSandbox`](websocket-protocol.md#sessionbindsandbox) — Binds this session's runtime to a Docker-sandboxed...
- [`session.bindSubstrate`](websocket-protocol.md#sessionbindsubstrate) — Binds this session's runtime to the *execution...
- [`session.clear_halt`](websocket-protocol.md#sessionclear_halt) — Packaged clients: HostClient.sessionClearHalt /...
- [`session.init`](websocket-protocol.md#sessioninit) — client_id is required and was missing from this...
- [`session.policy.close`](websocket-protocol.md#sessionpolicyclose) — Close a previously-opened policy session and drop...
- [`session.policy.open`](websocket-protocol.md#sessionpolicyopen) — Open a new in-runtime policy-scoping session and...

## skill (11)

- [`skill.adopt_pack`](websocket-protocol.md#skilladopt_pack) — The daemon call-site for governed pack adoption:...
- [`skill.enforce_deployment`](websocket-protocol.md#skillenforce_deployment) — The load-time enforcement bridge (Slice 4): gates...
- [`skill.export`](websocket-protocol.md#skillexport) — Exports a validated skill (the SkillOpt...
- [`skill.find`](websocket-protocol.md#skillfind) — Spreading-activation match against trigger edges.
- [`skill.gate_deployment`](websocket-protocol.md#skillgate_deployment) — Gates a skill's requested deployment capability...
- [`skill.import`](websocket-protocol.md#skillimport) — Imports a skill from a skill.export document as a...
- [`skill.ingest`](websocket-protocol.md#skillingest)
- [`skill.ingest_governed`](websocket-protocol.md#skillingest_governed) — The loader integration: ingests a skill *through*...
- [`skill.meta`](websocket-protocol.md#skillmeta) — Includes the lifecycle status (active /...
- [`skill.repair`](websocket-protocol.md#skillrepair)
- [`skill.report`](websocket-protocol.md#skillreport)

## skills (7)

- [`skills.distill`](websocket-protocol.md#skillsdistill) — extracted from execution traces via inference
- [`skills.domains_needing_evolution`](websocket-protocol.md#skillsdomains_needing_evolution)
- [`skills.evolve`](websocket-protocol.md#skillsevolve)
- [`skills.gate`](websocket-protocol.md#skillsgate) — Runs the promotion gate manually (it also runs...
- [`skills.ingest_distilled`](websocket-protocol.md#skillsingest_distilled)
- [`skills.ingest_provisional`](websocket-protocol.md#skillsingest_provisional) — Validation-gated ingest (SkillOpt-inspired).
- [`skills.list`](websocket-protocol.md#skillslist)

## speech (1)

- [`speech.prepare`](websocket-protocol.md#speechprepare) — Provisions the managed mlx-audio runtime (a uv venv...

## state (5)

- [`state.exists`](websocket-protocol.md#stateexists)
- [`state.get`](websocket-protocol.md#stateget)
- [`state.keys`](websocket-protocol.md#statekeys)
- [`state.set`](websocket-protocol.md#stateset)
- [`state.snapshot`](websocket-protocol.md#statesnapshot)

## supervision (4)

- [`supervision.decide`](websocket-protocol.md#supervisiondecide) — Errors when the intent is unknown — already...
- [`supervision.pending`](websocket-protocol.md#supervisionpending) — The batching half: one model call can cover every...
- [`supervision.subscribe`](websocket-protocol.md#supervisionsubscribe) — Re-subscribing replaces the filter; no disconnect...
- [`supervision.unsubscribe`](websocket-protocol.md#supervisionunsubscribe) — Happens automatically when the connection drops.

## sync (15)

- [`sync.append`](websocket-protocol.md#syncappend) — Record an op on any surface — the generic domain...
- [`sync.assistant_action.get`](websocket-protocol.md#syncassistant_actionput-syncassistant_actionget) — Put params: { record: SupervisedActionRecord };...
- [`sync.assistant_action.put`](websocket-protocol.md#syncassistant_actionput-syncassistant_actionget) — Put params: { record: SupervisedActionRecord };...
- [`sync.assistant_checkpoint.get`](websocket-protocol.md#syncassistant_checkpointput-syncassistant_checkpointget) — Put params: { checkpoint: AssistantCheckpoint };...
- [`sync.assistant_checkpoint.put`](websocket-protocol.md#syncassistant_checkpointput-syncassistant_checkpointget) — Put params: { checkpoint: AssistantCheckpoint };...
- [`sync.checkpoint`](websocket-protocol.md#synccheckpoint) — Compute + upload a device-side checkpoint at the...
- [`sync.fence_check`](websocket-protocol.md#syncfence_check) — The executor dispatch fence at the point of effect...
- [`sync.knowledge`](websocket-protocol.md#syncknowledge) — Read the synced knowledge facts, optionally pumping...
- [`sync.pump`](websocket-protocol.md#syncpump) — With org-scope sync on, each configured org's...
- [`sync.rebase`](websocket-protocol.md#syncrebase) — Cold bootstrap / straggler re-entry: re-anchor on...
- [`sync.record_intent`](websocket-protocol.md#syncrecord_intent) — Write the leased-execution intent ledger...
- [`sync.record_turn`](websocket-protocol.md#syncrecord_turn) — For a tool turn, provenance: "external" marks...
- [`sync.resume`](websocket-protocol.md#syncresume) — provenance is "external" for retrieved content and...
- [`sync.status`](websocket-protocol.md#syncstatus) — The device roster, this device's journal frontier...
- [`sync.transcript`](websocket-protocol.md#synctranscript) — provenance is "external" on a tool turn whose bytes...

## tasks (3)

- [`tasks.list`](websocket-protocol.md#tasks-daemon-native-deterministic-command-scheduler-car-releases72) — Params: none. Returns: an array of { id, name,...
- [`tasks.schedule`](websocket-protocol.md#tasks-daemon-native-deterministic-command-scheduler-car-releases72) — Params: { name, program, args?: string[], cadence:...
- [`tasks.unschedule`](websocket-protocol.md#tasks-daemon-native-deterministic-command-scheduler-car-releases72) — Params: { id } (bare id or full...

## tools (6)

- [`tools.cancel`](websocket-protocol.md#toolscancel) — Cooperative: fires the invocation's cancel token...
- [`tools.list`](websocket-protocol.md#toolslist) — The toolset actually in effect on this connection.
- [`tools.poll`](websocket-protocol.md#toolspoll) — status ∈ running | succeeded | failed | cancelled.
- [`tools.register`](websocket-protocol.md#toolsregister)
- [`tools.stream.subscribe`](websocket-protocol.md#toolsstreamsubscribe) — Subscribes this connection to the session runtime's...
- [`tools.unregister`](websocket-protocol.md#toolsunregister) — Removes the tool from both the runtime's canonical...

## verify (1)

- [`verify.monte_carlo`](websocket-protocol.md#verifymonte_carlo) — Static, no tools are called — same as verify.

## video (1)

- [`video.generate`](websocket-protocol.md#videogenerate) — audio_passthrough gate (Parslee-ai/car#185): when...

## vision (1)

- [`vision.ocr`](websocket-protocol.md#visionocr) — On-device text recognition.

## voice (16)

- [`voice.cancel_turn`](websocket-protocol.md#voicecancel_turn) — Cancels the in-flight voice turn.
- [`voice.dispatch_turn`](websocket-protocol.md#voicedispatch_turn) — Two-track sidecar pattern: a fast inference...
- [`voice.enroll_speaker`](websocket-protocol.md#voiceenroll_speaker)
- [`voice.list_enrollments`](websocket-protocol.md#voicelist_enrollments)
- [`voice.prepare_diarizer`](websocket-protocol.md#voiceprepare_diarizer) — downloads the diarization model
- [`voice.prepare_parakeet`](websocket-protocol.md#voiceprepare_parakeet) — downloads the Parakeet TDT model on first call...
- [`voice.prewarm_turn`](websocket-protocol.md#voiceprewarm_turn) — Issues a 1-token probe with prefer_fast: true so...
- [`voice.providers.list`](websocket-protocol.md#voiceproviderslist) — Stateless. Enumerates STT/TTS providers compiled...
- [`voice.remove_enrollment`](websocket-protocol.md#voiceremove_enrollment)
- [`voice.sessions.list`](websocket-protocol.md#voicesessionslist)
- [`voice.transcribe_stream.push`](websocket-protocol.md#voicetranscribe_streampush) — base64-encoded 16-bit signed PCM
- [`voice.transcribe_stream.start`](websocket-protocol.md#voicetranscribe_streamstart) — Pushes voice.event notifications with partials and...
- [`voice.transcribe_stream.stop`](websocket-protocol.md#voicetranscribe_streamstop)
- [`voice.tts_stream.cancel`](websocket-protocol.md#voicetts_streamcancel) — Aborts an in-flight TTS stream.
- [`voice.tts_stream.list`](websocket-protocol.md#voicetts_streamlist)
- [`voice.tts_stream.start`](websocket-protocol.md#voicetts_streamstart) — Begins streaming TTS synthesis.

## workflow (6)

- [`workflow.build_automation`](websocket-protocol.md#workflowbuild_automation) — Lowers the external-item automation recipe to a...
- [`workflow.chain`](websocket-protocol.md#workflowchain) — Inter-workflow chaining (EPIC H / H3): runs the...
- [`workflow.list_paused`](websocket-protocol.md#workflowlist_paused) — The discovery half of durable resume (EPIC H / H1):...
- [`workflow.resume`](websocket-protocol.md#workflowresume) — input is a JSON object of the human's response...
- [`workflow.run`](websocket-protocol.md#workflowrun) — Initial-state injection (EPIC H / H3):...
- [`workflow.verify`](websocket-protocol.md#workflowverify) — Structural rules (reported as error, so valid is...

## (top-level) (12)

- [`classify`](websocket-protocol.md#classify) — Matching: a bare number answers with that label...
- [`detokenize`](websocket-protocol.md#detokenize) — inverse of tokenize, decoded without skipping...
- [`embed`](websocket-protocol.md#embed)
- [`infer`](websocket-protocol.md#infer) — Supplying a non-null model is a hard pin.
- [`infer_stream`](websocket-protocol.md#infer_stream) — Explicit-model pinning is identical to infer: a...
- [`rerank`](websocket-protocol.md#rerank) — Rerank candidate documents against a query using a...
- [`search`](websocket-protocol.md#search) — Backend resolution (daemon-side, from its...
- [`synthesize`](websocket-protocol.md#synthesize) — Same filesystem caveat as transcribe for...
- [`tokenize`](websocket-protocol.md#tokenize) — Local models only (Qwen3 GGUF / MLX).
- [`transcribe`](websocket-protocol.md#transcribe) — Sandbox-crossing escape hatch (closes...
- [`verify`](websocket-protocol.md#verify) — Static verification only — no tools are called.
- [`web_fetch`](websocket-protocol.md#web_fetch) — Keyless (plain HTTP GET).

{% endraw %}
