Local development toolchain
Jotify CLI
Create manifests, validate permissions, preview extensions in a device shell and upload digest-bound draft versions with a signed artifact.
Create and validate
The CLI creates a credential-free jotify.app.json manifest. Validation rejects wildcard scopes, cross-target surfaces, traversal paths, embedded secrets and oversized manifests.
npm run jotify:app -- app init my-extension --name "My extension" --target site
cd my-extension
npm run jotify:app -- app validateLocal simulator
The simulator binds to loopback by default, injects no credentials and lets you inspect approved desktop, tablet and mobile extension frames.
jotify app dev --host 127.0.0.1 --port 4173Deterministic bundle
Pack creates a bounded .jotifyapp artifact with sorted file paths, per-file SHA-256 hashes and an aggregate digest. Symlinks, environment files, traversal paths and oversized assets fail closed.

