tuffite.json
A searchable configuration reference generated from the canonical schema.
Experimental source release. Production hardening and published SDK packages are still in progress.
The application manifest#
The root requires app and build. app defines identifier, security, and assets; build.shellApi defines code generation. productName and bundle are optional. Source and packaged application manifests have no schemaVersion. Unknown properties are rejected where additionalProperties is false. Validate with tuff check; type correctness alone does not guarantee route or permission semantics.
{
"$schema": "https://tuffite.org/schema/v2/tuffite.schema.json",
"productName": "My App",
"app": {
"identifier": "org.example.myapp",
"security": { "capabilities": [] },
"assets": []
},
"build": {
"shellApi": { "namespace": "myapp", "definitions": ["shell_api.d.ts"] }
}
}Explore configuration types#
Fields, required markers, enums, unions, and references below come directly from schemas/tuffite.schema.json. Filter by field or type name. A missing default means the schema does not declare one.
root
objectNo unknown fields$schemaJSON Schema URL used by editor validation.
apprequiredApplication identity, security, windows, native API, and assets.
buildrequiredCode generation, development package, web server, and debugging settings.
bundleResources included in the application package.
productNameApplication display and bundle name; defaults to the Cargo package name.
Application display name and default bundle name. Defaults to the Cargo package name. Use a portable filename (up to 128 UTF-8 bytes); spaces and Unicode are supported.
app
objectNo unknown fieldsidentifierrequiredApplication identifier, conventionally in reverse-domain form.
securityrequiredContent security policy and origin-scoped capabilities.
windowsInitial native window configurations.
assetsrequiredExplicit mappings from request origins/paths to resource files.
networkApplication network policy.
utilitiessecurity
objectNo unknown fieldscspFrontend Content-Security-Policy.
Pattern: ^[^\r\n]+$
capabilitiesrequiredNative permissions for explicitly matched origins.
window
objectNo unknown fieldslabelrequiredApplication-visible window label.
urlrequiredInitial page URL for the native window.
titlexywidthrequiredInitial window width.
min: 1 · max: 16384
heightrequiredInitial window height.
min: 1 · max: 16384
focuseddecorationsminWidthmin: 1 · max: 16384
minHeightmin: 1 · max: 16384
maxWidthmin: 1 · max: 16384
maxHeightmin: 1 · max: 16384
build
objectNo unknown fieldsdevPackageDirectory of the refreshed native development package.
devUrlLoopback frontend URL used by the authenticated dev override.
beforeDevCommandCommand started before the native development window.
beforeBuildCommanddevtoolsPortLoopback Chrome DevTools Protocol port.
min: 1 · max: 65535
profileshellApirequiredNamespace and declaration files for typed code generation.
build.shellApi
objectNo unknown fieldsnamespacerequiredPattern: ^[A-Za-z_$][A-Za-z0-9_$]*$
definitionsrequiredfacadebundle
objectNo unknown fieldsexecutableresourcesApplication files and directories to include in the package.
iconsbundle.icons
objectNo unknown fieldsmacosProject-relative .icns icon; defaults to Tuffite.
windowsProject-relative .ico icon; defaults to Tuffite.
originCapability
objectNo unknown fieldsidentifierrequiredPattern: ^[A-Za-z0-9_-]+$
descriptionoriginsrequiredshellApiexploreroriginCapability.explorer
objectNo unknown fieldscreateexecuteJavaScriptnetwork
objectNo unknown fieldsdisableHttp2maxResponseBytesmin: 1 · max: 5242880
timeoutSecondsmin: 1 · max: 300
assetRoute
objectNo unknown fieldsoriginsrequiredpathsrequiredfiledirectoryshellApiEntry.variant2
objectNo unknown fieldsmethodrequiredPattern: ^(?:\*|(?:[A-Za-z_$][A-Za-z0-9_$]*\.)+(?:[A-Za-z_$][A-Za-z0-9_$]*|\*))$
allowdeny