Words and questions

Glossary & questions

TEPP's vocabulary in plain language — each term with the specification statements that define it — and short answers to the questions people ask first.

Jump to the questions ↓

Glossary

association (kind 17710)
The subject's own replaceable event naming its guardians — publicly as p tags, privately encrypted to itself, or both. The newest valid one applies.
ASSOC-001ASSOC-018
binding carrier
A policy carrier written by a current guardian at one of the subject's two binding addresses. Only binding carriers apply to the subject directly.
ADDR-001TERM-003
blind(G,S)
The sealed binding address of a guardian and a subject: a hash that only the two of them can compute. To anyone else it is noise.
ADDR-005
category
One of eight permission sections: interact, view or extend, joined to npub, relay or event. There is no extend/event.
POL-025NF-015
cohort / modifier
The two shapes of the starter profiles: an allow-shaped cohort is a complete policy; a deny-shaped modifier is partial.
PROF-034
construct
The merged permission state the engine assembles and enforces: admission entries, deny gates and the global set.
TERM-005
construct age
Time since the last successful refresh. By default, past a day every verdict notes it, and past a week signing first awaits one refresh attempt.
CONS-177CAPS-023CAPS-024
coverage
On output, every element of a request must be covered by a non-void interact entry — or, for an event, be the subject's own.
OUT-005OUT-030OUT-031
demand (rebroadcast)
The one thing a restriction entry can ask of the signer: to add NIP-70's ["-"] tag to the event it signs.
TERM-022OUT-040NF-082
deny beats harvest
A party a deny gate names is never an extension source; nothing is harvested from it.
CONS-012
deny gates
Pubkeys, events, relays and shared blocklists that are out, full stop. A deny gate over-rules every grant, wherever the engine meets it.
POL-019RESTR-040
deny sweep
On output, following what a request references down the chain — within bounds — and deny-checking it: the subject does not amplify denied material.
OUT-012OUT-020
destination whitelist regime
Switched on by any direct interact/relay grant: the subject's own material is then hosted only on member relays.
OUT-053OUT-056
determinism tuple
(construct, event, direction, instant, world, inputs): identical tuples give identical verdicts, traces and orderings.
INTRO-002
enforcing locus
A TEPP signer or a TEPP client, each running the full construct. A relay is not one.
TERM-020NF-094
entry
One resolved admission in the construct: a mode, a scope, a member and the restriction sets that come with it.
TERM-006
finding
A typed report explaining the construct, a verdict or the ceremony. Every drop, skip or failed load emits one, bar a few stated exceptions.
TRACE-002CONS-117
general carrier
A policy carrier at an address that names no subject — a curator's, say. It binds nobody directly; households reach it only through extension.
ADDR-004CONS-030
global set
The subject-wide gate: every guardian's global restriction entries, and those of the profiles they reference, as one set. A deny from it blocks, in both directions.
CONS-003RESTR-037
grant-scoping / restriction-driving
The two roles of a profile reference: on a permission it narrows that grant; as a global entry it joins the global set.
PROF-013PROF-014PROF-016
guardian
A key named in the subject's current association. Each guardian publishes and edits their own policy.
TERM-002NF-039
high-water mark
Anti-rollback state per coordinate: an older copy never displaces what the locus has accepted. The marks of the association and the binding coordinates even survive losing the store.
CONS-159CONS-163CONS-168ASSOC-037
hit
What admits an event on input: a relay hit (a permitted place), an npub hit (a permitted publisher), an event hit (a permitted id) or the self hit. One is enough. For encrypted events only an interact npub hit on the recovered author, or the self hit, counts.
IN-005IN-013IN-016IN-019
household channel
The subject's correspondence with its current guardians, in both directions.
TERM-023
implied guardian entry
An interact/npub entry the engine creates for every current guardian, with no restrictions of its own — so the subject's line to its guardians exists because the regime exists. The global set still binds it.
TERM-009CONS-068CONS-069
instant
The time of an evaluation, supplied to the engine together with its local weekday and minute-of-day. The engine reads no clock of its own.
TERM-011INTRO-004
kind0 clause
A metadata event (kind 0) — someone's name and picture — that is not encrypted renders without a hit, so the subject can see who a stranger is. Input only.
IN-044NF-052
known world
A locus's durable store of everything it has accepted; the construct is assembled from it.
CONS-119
layer
What decided a verdict — one of fifteen, from global and blocklist to covered and refusal.
TRACE-006
loading rule
What cannot be loaded is not in the construct — and is reported.
CONS-105
map
Which of a source's categories are harvested, and whether as interact or demoted to view. A view category can never be promoted.
POL-051CONS-040POL-088
mode: view / interact
View lets something reach the subject — never encrypted material. Interact also lets the subject act on it: tag, answer, message. Only interact covers anything on output.
TERM-007IN-021OUT-034
monitor copy
The oversight copy of a signed event, published to the monitorRelays of the grants that covered it.
OUT-064
opaque
Material whose surface is hidden by encryption. Opacity is a property of the material, not of a kind number.
OPQ-001NF-063
oracles
The only three ways a client can use the subject's key at a TEPP signer: sign_event, nip44_encrypt and nip44_decrypt. Each is evaluated — a policy read aside.
TERM-018OPQ-059SURF-050
peer, curator, operator
A peer is another subject whose permissions can be inherited; a curator is any party whose general carriers are adopted; an operator is the key a relay's information document names.
CONS-024CONS-030CONS-031
permission
One grant in a policy document: members, its own restrictions, an optional profile, routing, and optionally an extension.
POL-035
policy carrier (kinds 37710, 37711)
The event that carries a policy document: open, or sealed — encrypted to the subject.
EVT-005EVT-006POL-001
policy document
The JSON a carrier holds: global entries, deny gates and permissions. {} is a valid, empty document.
POL-002POL-006
policy read
A decrypt request for TEPP's own sealed artifacts, answered without a verdict, so that a keyless client can load its policy.
OPQ-073
provenance
What every harvested entry records: the issuing carrier, the route, and the carrier it was harvested from.
CONS-048
ratification
The subject signing exactly the association that a validated, outstanding offer describes — the only way the guardian set changes inside the regime.
CERE-001CERE-014CERE-035
re-association offer (kinds 7710, 7711)
A current guardian's signed proposal of a successor association, open or sealed.
EVT-003EVT-004CERE-010
recovered author
Who an encrypted message is really from: the outermost signed layer that is not a one-time gift wrap.
OPQ-039
reduction
Peeling opaque material, layer by layer, to recover who it is from and what it names. The plaintext is then discarded.
TERM-016OPQ-012OPQ-051
reduction record
A locus's bounded memory of whom it encrypted for and which messages it reduced — recipients and surfaces, never content. It never leaves the locus.
TERM-019OPQ-112
refresh tick
A background refresh: newer verified material advances the store; silence changes nothing.
CONS-126CONS-148CONS-151
refusal
The assembly refusing over a contradiction: nothing is signed and every evaluation denies.
CONS-108CONS-114
regimes
The four ways a restriction set resolves: a matching deny denies; else a matching allow allows; else a set without allow entries allows; else it denies — a whitelist closes over what it does not name.
RESTR-013
render walk, wall
How deep an admitted event renders. The walk follows references and deny-checks them; a wall stops one branch, and everything above it stays visible.
IN-007IN-036
restriction entry
Six predicate fields — polarity, kinds, weekdays, time, direction, opacity — and, on allow entries, the optional rebroadcast demand.
POL-008POL-016
restriction profile (kind 7712)
An immutable, public, content-addressed set of restriction entries. It binds nobody until a carrier references it, and can never admit anyone.
TERM-021PROF-001NF-028
scope: npub / relay / event
People, places and things.
TERM-008
sealed channel / open channel
The subject's encrypted and plain correspondence. Outbound, the sealed channel is exactly as permissive as the open one.
TERM-024TERM-025OPQ-119
space
A relay that runs the engine for a regime of its own, deciding what it accepts and serves.
LOCI-030
subject
The identity whose world is bounded — a child's key, in the motivating case. Its own engine assembles and enforces its construct.
TERM-001
TEPP client (key loaded, keyless)
A client running the engine: the home of input. Key loaded, it holds the key; keyless, it reads its policy through its signer.
LOCI-024LOCI-025LOCI-027
TEPP signer
A signer running the engine: the home of output, policing every use of the subject's key.
LOCI-028LOCI-029
trace
What the engine reports beside a verdict: the deciding layer, a reason where it has one, the attribution, walls and findings.
TRACE-001
trust extension
Harvesting grants from what a permission's members publish or are permitted — via peer, via curator, or through a relay's operator. One hop; each harvested grant is held to both the adopting and the source permission's restrictions.
CONS-018CONS-042CONS-044
unbound
The state of a subject with no valid association: its signer signs nothing and every evaluation denies. Fail-closed, not free.
ASSOC-020ASSOC-021ASSOC-022
unloaded
The finding that reports something not loaded: surfaced to the subject, and sent to the guardians — as an ordinary, policed message — once it has stood a day (by default).
TRACE-053CONS-107LOCI-044
void
An entry is void for an evaluation when one of its restriction sets resolves to deny: it contributes nothing, and denies nothing by itself — save that a direct interact/relay grant keeps the destination whitelist on even while void.
RESTR-041RESTR-042RESTR-043

Questions people ask first

Can guardians read the subject's private messages?

No. Nothing in TEPP copies a guardian into a permitted private channel: it is private, guardians included. The subject's own engine reads the plaintext on the device to find out who a message involves, evaluates that, and discards it.

What a household can learn is who, never what: the trace on the device names the correspondents, and where a guardian routes a monitor copy, a private send arrives there as ciphertext — volume and timing only. A household that wants less privacy than that has one option: close the channel.

OPQ-051 · OPQ-124 · TOOL-036 · TOOL-037 · NF-078

Who decides who the guardians are?

The subject. Its own signed association names the guardians. Inside the regime the set changes only when the subject ratifies an offer made by a current guardian — mutual consent as two ordinary signatures. Whoever holds the subject's key can also sign a newer association outside the regime; that act is public, and every engine follows it.

ASSOC-001 · ASSOC-038 · CERE-001 · CERE-014

What if two guardians disagree?

Grants add up: any one guardian's grant is enough to admit. Denies add up too, and any guardian's deny over-rules every grant. Each guardian edits only their own policy, so a disagreement about how wide a grant should be is settled between the guardians, outside the engine. A deny that names a current guardian is a contradiction: the assembly refuses — nothing is signed and nothing reaches the subject until it is lifted.

CONS-001 · CONS-003 · NF-039 · CONS-095

Why can the subject see a stranger in the feed, but not reply to them?

Because reading is not acting. An event reaches the subject on one hit — for instance, a permitted friend published it — and what it references renders unless something there is denied. Signing a reply that tags the stranger is an act, so it needs a grant on the stranger. The trace names the first uncovered element, so the subject knows what to ask a guardian for.

IN-005 · IN-014 · IN-036 · OUT-030 · OUT-035

Does a relay enforce TEPP?

No relay enforces a subject's regime. Enforcement happens at the subject's own TEPP signer and TEPP client. A relay may run the same engine for rules of its own — a space — and publish them as open carriers that any household can choose to adopt.

NF-094 · LOCI-030 · CONS-038 · CONS-039

What happens when relays are unreachable?

The engine keeps enforcing what it already holds: relay silence never removes a guardian's policy, and nothing is refused for being stale. Staleness is measured instead — after a day every verdict carries an age finding, and after a week signing first waits for one refresh attempt (both by default). Whatever cannot be loaded is reported: to the subject at once, and to the guardians once it has stood for a day, by default.

CONS-010 · CONS-151 · CONS-177–CONS-181 · CONS-107 · CAPS-023 · CAPS-024 · CAPS-029

Can someone push rules onto a household?

No. A restriction profile, or a curator's published carrier, binds nobody until one of the household's guardians adopts it. A profile never admits anyone and never undoes a deny — though in the global set its allow entries do add to the other guardians' whitelists. And adopting a curator is a standing choice: what the curator adds later arrives at the next refresh, with no further guardian act.

PROF-001 · PROF-021 · PROF-022 · CONS-023 · CONS-056 · NF-028

How does a regime end?

Outside the protocol: the subject deletes the association or signs a newer valid one — both signed, public acts — or stops running TEPP software. TEPP defines no release ceremony and no terminal state; policy only shrinks by a positive, signed act.

NF-013 · NF-014 · ASSOC-038

Is this only for children?

The motivating case is parents and a child, but the machinery is general: a permissionless system for the creation of permissioned environments. Any subject can name any guardians — and a relay can use the same engine for its own community's rules.

What can TEPP not do?

It cannot provide a channel the guardians have not permitted: where the guardian is the threat, TEPP is not the remedy. It cannot see encryption it does not recognise, or a message hidden in an ordinary-looking note. It cannot stop whoever holds the key from signing outside a TEPP signer; leaving the regime that way means signing a newer association, which is public. And it cannot protect a post on a relay that does not implement NIP-70.

TOOL-039 · OPQ-006 · ASSOC-038 · TOOL-028