---
name: Aziel Eliab Runtime
description: >-
  One door — discover, route, refuse. FragGate over the catalog: hashed
  registry, DecisionGATE before exec, ask/refuse ledger. Dual surface —
  agent/MCP has no technical UI chrome; Worker UI, Flutter mobile/, local
  install, and counted /download stay complete human software. 1.6.2 widens
  the public door to sensible advisory engines; stubs still refuse. 1.6.1
  lists every major OpenAPI/MCP/HTTP client. 1.6.0 FragGate door cut. Kernel:
  https://github.com/AzielEliab/fraggate
---

# Aziel Eliab Runtime

This is software you use in chat. **One door — discover, route, refuse.** There is no extra technical UI for the agent surface. Show the user the software output, then take the next input.

FragGate kernel: https://github.com/AzielEliab/fraggate (FG-0.1)

## Dual surface (product law)

1. **Agent / MCP** — Software runs 100% through the agent. Display `display.title`, `display.summary`, and `display.fields` in the AI client. Feed the next input back into the same product. Session ids, receipts, OpenAPI, and HTTP stay invisible unless the user asked for them.
2. **Human software** — Unchanged and required. Worker homepage, Flutter `mobile/`, local install, and counted `/download` remain complete developed software. Do not gut human UIs.

## How an agent uses this like software

1. **Discover.** `runtime_skill` or `fraggate_list` (hashed registry: live / stub / local_only). `fraggate_describe` one name. `fraggate_verify` a name or digest.
2. **Route.** `fraggate_call` with a CallEnvelope `{ name|slug, op, payload, claim? }`. DecisionGATE runs before any exec side effect. Live allowlist: every sensible advisory / score / classify / gate / search / preview / render / verify / hash / receipt / game / overlay / route / status engine already hosted in-process. VeilLock stays local_only. Stub verbs still refuse.
3. **Refuse.** Unknown names return `FG-HALLUC-TOOL`. Stubs and `local_only` do not execute on the public mesh. Gate BLOCK/REVISE is ledgered; no handler.
4. **Show the output.** Results are `{ display, result, ledger_tip? }`. Show `display` to the user.
5. **Take the next input.**

Named live modules still on the thin tools/list: `decisiongate_check`, `library_lookup` (read-only corpus).

Do **not** walk the user through `runtime_session_open` → policy → exec → receipt → close. Those tools, `runtime_run`, raw `*_health`, and `runtime_manifest` are **advanced/internal**.

Do **not** call flat `{slug}_{op}` names (1.5.0 pile). They are not in `tools/list`. That is hallucination with a receipt.

HTTP `POST /p/{slug}/{op}` is still a **proxy**. Proxy without a session receipt is **not** exec. Mesh is **not** claimed on this public surface.

Every catalog slug is a true engine. Cloudflare isolate is the jail. Hosted AZAI is protocol mirror + Lamb check, **not** the blend. Identity is **Aziel Eliab** only.

**1.6.2 = public door covers sensible advisory engines**; stub verbs still refuse. VeilLock stays local_only. MCP tools/list stays the thin FragGate surface.
**1.6.1 = full compatible AI client list** (not only ChatGPT / Grok / Venice).
**1.6.0 = FragGate door** over the catalog (hashed registry, thin MCP, DecisionGATE before exec, ask/refuse ledger). Kernel: https://github.com/AzielEliab/fraggate
**1.5.0 = agent-native cut** on 1.4.1 production gates (display envelopes, flat product-verb MCP, `runtime_run`).
**1.4.1 = 1.4.0 engine-runtime + production gates** (`GET /v1/ready`, HEAD, no-store authority JSON, receipt cap 64, session TTL 6h, per-IP rate limits, optional `RUNTIME_TOKEN` on session mutate).
**1.4.0 = catalog + pull + proxy + session + in-process engines** for **every** catalog Software slug.
**1.3.0 = true engine runtime** for listed portable slugs (in-process) + session + pull/proxy.
**1.2.0 = session-runtime** (receipt chain; exec still `upstreamFetch`ed product Workers).
**1.1.0 = catalog + pull + proxy** that started calling itself a runtime. Useful front doors. Not exec.

True engine exec on *this* Worker is still:

`open → policy → exec(slug, op, payload) → receipt → close`

Agents should not narrate that chain. `fraggate_call` is the default exec path. For **true-engine slugs** (`ark, azai, azbot, azclce, aziel-corpus, azieltether, azos, chronolock, codelock, decisiongate, employeelock, foldlock, forgereceipts, glossafilter, godlock, mialock, miragegrid, postking, shadowlock, spectrallock, staticclock, temporallock, trajectorylock, veillock, vibelock, whistlelock, zsolver`) `exec` resolves the slug to a vendored module, computes `engine_digest` = SHA-256 of that artifact's bytes, runs the op **inside this Worker isolate** (the jail), wipes scratch buffers, and the receipt includes `engine_digest`, `engine_slug`, `engine_op`, `ran_in: "aziel-runtime"`. `GET /v1/health` `engine_slugs` equals `true_engine_slugs` equals the catalog.

If an op **cannot** run without external bindings (KV / D1 / AI / live media), that **op** is marked `mode: "proxy_fallback"` while the slug stays a true engine. It does **not** pretend the binding ran here.

`GET/POST /p/{slug}/{op}` is still a **proxy**. Proxy without a session receipt is **not** exec.

Cloudflare's Worker / Durable Object isolate **is** the jail. No extra guest isolate is claimed. The receipt still requires that engine's digest.

Closest true *local blends* in the mesh remain: `azai serve`, `forgereceipts ui`, `azos ui`.
Hosted / in-process AZAI is still protocol mirror + Lamb check, **not** the blend.

Author: **Aziel Eliab**. Identity is Aziel Eliab only.
License: Apache-2.0. Forks are welcome and always allowed.
Version: 1.6.2
Role: engine-runtime (layer: catalog+pull+proxy+session+in-process-engines+fraggate)
Door: fraggate
Kernel: https://github.com/AzielEliab/fraggate
Host: https://godlock.uk/runtime/
Everblooming sigil: https://godlock.uk/runtime/sigil.png
Products: 27 (vibelock, veillock, codelock, godlock, shadowlock, temporallock, forgereceipts, decisiongate, zsolver, azos, glossafilter, miragegrid, staticclock, chronolock, postking, azclce, ark, azai, spectrallock, azbot, employeelock, foldlock, whistlelock, trajectorylock, mialock, azieltether, aziel-corpus)
True-engine slugs: ark, azai, azbot, azclce, aziel-corpus, azieltether, azos, chronolock, codelock, decisiongate, employeelock, foldlock, forgereceipts, glossafilter, godlock, mialock, miragegrid, postking, shadowlock, spectrallock, staticclock, temporallock, trajectorylock, veillock, vibelock, whistlelock, zsolver
engine_slugs: ark, azai, azbot, azclce, aziel-corpus, azieltether, azos, chronolock, codelock, decisiongate, employeelock, foldlock, forgereceipts, glossafilter, godlock, mialock, miragegrid, postking, shadowlock, spectrallock, staticclock, temporallock, trajectorylock, veillock, vibelock, whistlelock, zsolver
Modules: `src/engines/{slug}.js` for every catalog slug (ark, azai, azbot, azclce, aziel-corpus, azieltether, azos, chronolock, codelock, decisiongate, employeelock, foldlock, forgereceipts, glossafilter, godlock, mialock, miragegrid, postking, shadowlock, spectrallock, staticclock, temporallock, trajectorylock, veillock, vibelock, whistlelock, zsolver)
Packaging: Worker session + in-repo CLI (`node cli/aziel-runtime.mjs`). **No counted runtime tarball.**

Always send `User-Agent: Mozilla/5.0`. Cloudflare Workers may 403 an empty agent.
Do **not** invent Zenodo DOIs. Cite `/cite.json`. Download counters are **not** incremented on pull, skill, health, proxy, or session exec.

## Session (advanced / internal)

Prefer `fraggate_call`. This chain is the raw object:

1. `POST https://godlock.uk/runtime/v1/session/open` — session id, start time, policy defaults, empty receipt chain.
2. `POST https://godlock.uk/runtime/v1/session/{id}/policy` — allow slugs/ops, payload size cap, no download-counter side effects unless explicitly requested (this Worker still has no download KV).
3. `POST https://godlock.uk/runtime/v1/session/{id}/exec` body `{slug, op, payload}` — record intent, run the **local in-process engine** for that slug (`engine_digest` + `ran_in: aziel-runtime`); only binding-only ops are per-op `proxy_fallback`. Append a **hash-chained execution receipt owned by this session**. Returns `display` + `result` + `receipt`.
4. `GET https://godlock.uk/runtime/v1/session/{id}/receipt` or `.../receipts` — last receipt / full chain (verifiable locally).
5. `POST https://godlock.uk/runtime/v1/session/{id}/close` — seal. Further exec is 409.

CLI (talks to this Worker, or `--local` filesystem session; prefers local engine modules):

```bash
node cli/aziel-runtime.mjs session open
node cli/aziel-runtime.mjs session policy --allow-slugs azclce
node cli/aziel-runtime.mjs session exec azclce score '{"r":"login button blue","d":"login form submits","p":"login button submits"}'
node cli/aziel-runtime.mjs session receipt
node cli/aziel-runtime.mjs session close
```

## Bootstrap (front doors — still useful)

1. `GET https://godlock.uk/runtime/v1/skill` — this markdown.
2. `GET https://godlock.uk/runtime/v1/runtime.json` — machine manifest (`version=1.6.2`, `role=engine-runtime`, `door=fraggate`, every catalog slug in `engine_slugs` / `true_engine_slugs`, `authoritySnapshot` + `version_history`). Same JSON: `GET https://godlock.uk/runtime/v1/runtime`.
   FragGate: `GET https://godlock.uk/runtime/v1/fraggate` · `GET https://godlock.uk/runtime/v1/fraggate/list` · `POST https://godlock.uk/runtime/v1/fraggate/call`.
   Also `GET https://godlock.uk/runtime/v1/ready` (200 only if SESSION binding is up; 503 if `REQUIRE_TOKEN=1` and `RUNTIME_TOKEN` is missing).
3. `GET https://godlock.uk/runtime/v1/bundle` — every product skill URL + invoke prefix.
   Alias: `GET https://godlock.uk/runtime/v1/pull?all=1`.
4. `GET https://godlock.uk/runtime/v1/pull/{slug}` — name, version, skill URL, counted download, install.sh, ops.
5. `GET https://godlock.uk/runtime/v1/pull/{slug}/skill` — product skill markdown (proxied / cached).
6. Proxy (not exec): `GET` or `POST https://godlock.uk/runtime/p/{slug}/{op}`.

You do **not** need to open each product homepage.

## Compatible AI clients

Assistants / clients that can call OpenAPI, MCP, or HTTP tools:

- ChatGPT (GPT Actions / OpenAI)
- Grok (xAI)
- Venice
- Claude (Anthropic Desktop / custom tools)
- Cursor (MCP)
- Glama (Install Server / MCP)
- Perplexity
- Microsoft Copilot / Bing
- Google Gemini / Vertex AI
- Mistral
- Meta AI
- Apple Intelligence / Applebot surfaces
- Amazon Q / Amazonbot tooling
- DuckAssist / DuckDuckGo AI
- You.com
- Cohere
- plus other MCP/OpenAPI-capable assistants

Practical pull + call (do not invent steps for every crawler):

- **ChatGPT** — GPT Actions → Import from URL → `https://godlock.uk/runtime/openapi.json`
- **Grok** — custom tool / OpenAPI / MCP remote → `https://godlock.uk/runtime/openapi.json` or `POST https://godlock.uk/runtime/mcp`
- **Venice** — custom HTTP tools / OpenAPI → same OpenAPI URL
- **Claude Desktop** — MCP stdio `node cli/mcp-stdio.mjs` (see docs/GLAMA.md) or remote `POST https://godlock.uk/runtime/mcp`
- **Cursor (MCP)** — same stdio config or remote `POST https://godlock.uk/runtime/mcp`
- **Glama** — Install Server via glama.json + Dockerfile CMD `["node", "cli/mcp-stdio.mjs"]`
- **Any installer / agent** — `GET https://godlock.uk/runtime/v1/skill` then `fraggate_list` / `fraggate_call`. Session tools and `runtime_run` are advanced/internal. `/p/{slug}/{op}` is proxy only.

MCP is a **thin FragGate door** (≤ 20 tools): `runtime_skill`, `fraggate_list`, `fraggate_describe`, `fraggate_verify`, `fraggate_call`, `decisiongate_check`, `library_lookup`, plus catalog helpers `runtime_bundle` / `runtime_pull`. Advanced/internal: `runtime_run`, `runtime_manifest`, `runtime_session_*`. Flat `{slug}_{op}` names are **not** listed. Public, no OAuth.


## Endpoints (this Worker)

| Method | Path | What |
|--------|------|------|
| POST | `/v1/session/open` | Create session + genesis receipt. |
| POST | `/v1/session/{id}/policy` | Attach allow rules. |
| POST | `/v1/session/{id}/exec` | In-process engine for every catalog slug (`engine_digest`). Binding-only ops may be per-op proxy_fallback. Hash-chained receipt. |
| GET | `/v1/session/{id}/receipt` | Last receipt (verifiable). Includes engine_digest when local. |
| GET | `/v1/session/{id}/receipts` | Full receipt chain. |
| POST | `/v1/session/{id}/close` | Seal session. |
| GET | `/v1/skill` | This markdown. Does not increment downloads. |
| GET | `/v1/runtime.json` | Machine manifest. Authority with health: version=1.6.2, role=engine-runtime, door=fraggate, top-level registry_digest, all catalog slugs are true engines. |
| GET | `/v1/fraggate` | FragGate door summary (registry_digest; live / stub / local_only product counts; stub_op_count). |
| GET | `/v1/fraggate/list` | Hashed registry entries. |
| GET | `/v1/fraggate/describe` | Describe one name (`?name=` / `?slug=`). |
| POST | `/v1/fraggate/verify` | Verify a name or digest. |
| POST | `/v1/fraggate/call` | CallEnvelope → DecisionGATE → handler or refuse. |
| GET | `/v1/runtime` | Alias of `/v1/runtime.json` (same machine manifest). |
| GET | `/v1/ready` | Readiness. 200 if SESSION binding is up. 503 if `REQUIRE_TOKEN=1` and `RUNTIME_TOKEN` missing. |
| HEAD | `/v1/health`, `/v1/ready`, `/v1/runtime.json`, `/v1/skill` | 200 + `X-Aziel-Runtime-Version` / `X-Aziel-Runtime-Role`. |
| GET | `/v1/bundle` | Compact bootstrap of every product. |
| GET | `/v1/pull?all=1` | Alias of `/v1/bundle`. |
| GET | `/v1/pull/{slug}` | Pull record for one product. |
| GET | `/v1/pull/{slug}/skill` | Product skill markdown. |
| GET | `/v1/catalog.json` | Full catalog (discover). |
| GET/POST | `/p/{slug}/{op}` | **Proxy only** — not exec. Service binding preferred. |
| GET | `/openapi.json` | Combined OpenAPI 3.1. |
| POST | `/mcp` | JSON-RPC MCP-over-HTTP. |
| GET | `/cite.json` | How to cite Aziel Eliab software and the Digital Library. Aka Aziel Elroi Eliab. No invented DOIs. |
| GET | `/llms.txt` | Plain-text catalog + citation rules for crawlers. |
| GET | `/ai.txt` | Alias of `/llms.txt`. |
| GET | `/robots.txt` | Allow / for Google and major AI bots. No GPTBot Disallow. |
| GET | `/sitemap.xml` | Catalog urlset. |
| GET | `/sitemap-index.xml` | Catalog + Digital Library + godlock.uk + live product Worker sitemaps. |
| GET | `/v1/health` | Liveness. |

Library front door: https://www.azielcorpuslibrary.net/runtime  
Library engine manifest (same as this Worker): https://www.azielcorpuslibrary.net/runtime/v1/runtime.json  
**Not** the engine manifest: https://www.azielcorpuslibrary.net/v1/runtime is Digital Library package discovery (aziel-corpus), not aziel-runtime.

## Operator token (session mutate)

When `REQUIRE_TOKEN=1`, OpenAPI / MCP / HTTP Actions that **exec** (ChatGPT, Grok, Venice, Claude, Cursor, Glama, and other listed clients) must send `Authorization: Bearer $RUNTIME_TOKEN` (Wrangler secret — one operator token, not per-user). Catalog, skill, OpenAPI, health, pull, FragGate list/describe/verify, MCP `tools/list`, and proxy `/p/{slug}/{op}` stay public. Proxy is not exec.

## Example (Mozilla/5.0)

```bash
curl -s -A 'Mozilla/5.0' https://godlock.uk/runtime/v1/skill
curl -s -A 'Mozilla/5.0' https://godlock.uk/runtime/v1/runtime.json
SID=$(curl -s -A 'Mozilla/5.0' -X POST https://godlock.uk/runtime/v1/session/open -H 'content-type: application/json' -H "Authorization: Bearer $RUNTIME_TOKEN" -d '{}' | jq -r .session.id)
curl -s -A 'Mozilla/5.0' -X POST https://godlock.uk/runtime/v1/session/$SID/policy \
  -H 'content-type: application/json' -H "Authorization: Bearer $RUNTIME_TOKEN" \
  -d '{"allow_slugs":["azclce"],"max_payload_bytes":8192}'
curl -s -A 'Mozilla/5.0' -X POST https://godlock.uk/runtime/v1/session/$SID/exec \
  -H 'content-type: application/json' -H "Authorization: Bearer $RUNTIME_TOKEN" \
  -d '{"slug":"azclce","op":"score","payload":{"r":"login button blue","d":"login form submits","p":"login button submits"}}'
curl -s -A 'Mozilla/5.0' https://godlock.uk/runtime/v1/session/$SID/receipt
curl -s -A 'Mozilla/5.0' -X POST https://godlock.uk/runtime/v1/session/$SID/close -H "Authorization: Bearer $RUNTIME_TOKEN"
```

Proxy (not exec — no runtime-owned receipt):

```bash
curl -s -A 'Mozilla/5.0' -X POST https://godlock.uk/runtime/p/azclce/score \
  -H 'content-type: application/json' \
  -d '{"r":"login button blue","d":"login form submits","p":"login button submits"}'
```

## Honesty

Every catalog Software slug is a true engine (`true_engine_runtime: true`). `engine_slugs` equals `true_engine_slugs`: ark, azai, azbot, azclce, aziel-corpus, azieltether, azos, chronolock, codelock, decisiongate, employeelock, foldlock, forgereceipts, glossafilter, godlock, mialock, miragegrid, postking, shadowlock, spectrallock, staticclock, temporallock, trajectorylock, veillock, vibelock, whistlelock, zsolver. Some ops remain per-op `proxy_fallback` when they need product-Worker bindings (AZ-OS session/exec/lattice; Aziel Digital Library live D1 / Whisper / OCR). Cloudflare isolate is the jail; `engine_digest` is still required for local exec.

**1.4.1 production gates (unchanged in 1.6.2):** `GET /v1/ready` is 200 only if the SESSION Durable Object binding is up; **503** if `REQUIRE_TOKEN=1` and the `RUNTIME_TOKEN` secret is missing (fail closed). Authority JSON is `Cache-Control: no-store`. When `REQUIRE_TOKEN=1`, session mutate (open/policy/exec/close) and MCP session tools / `runtime_run` / `fraggate_call` require `Authorization: Bearer …` or `X-Aziel-Runtime-Token` (one operator token). Catalog / health / runtime / skill / pull / FragGate list / OpenAPI / MCP `tools/list` stay public. Proxy `/p/{slug}/{op}` stays public and is **not** exec. Receipt cap 64. Session TTL 6h. Per-IP rate limits apply.

GodLock and MirageGrid are not VPNs. ForgeReceipts is not legal advice. ZionPattern Solver caps confidence at 75% and does not solve cases. VeilLock does not inject into FaceTime. AZ-CLCE detects inconsistency, not intent. ChronoLock is advisory only. The ARK is not a kernel. AZAI hosted /v1 is a protocol mirror + Lamb check, not a paid-key proxy and **not** the local blend. Jeeves is not sovereign. SpectralLock hosted overlay is a 256px preview. EmployeeLock is not a court. FoldLock is not zip. WhistleLock is not a mailer. TrajectoryLock is not a certified forensic instrument. M.I.A.Lock Doe hits are leads, not IDs. Aziel Digital Library is not a 26-card index. AzielTether is not a VPN.

## Cite

Eliab, Aziel. (2026). Aziel Eliab Runtime 1.6.2 [Software]. Apache-2.0. https://godlock.uk/runtime/

Primary name: Aziel Eliab. Also known as Aziel Elroi Eliab (alternateName only).
Digital Library: Eliab, Aziel. (2026). Aziel Digital Library [Software]. Apache-2.0. https://www.azielcorpuslibrary.net/
Machine-readable: https://godlock.uk/runtime/cite.json · https://www.azielcorpuslibrary.net/cite.json
GitHub: https://github.com/AzielEliab/aziel-runtime
