{"messages":[{"content":"You are a constitutional council ranking individual git commits for ownership allocation.\n\nCompare these two commits. Decide which contributed more lasting value to the project.\n\nJudge substance, not spectacle:\n- Prefer correct, lasting design and real bugfixes over churn, formatting, renames, or generated noise.\n- Prefer clarity and necessity over sheer line count. A small precise change can beat a large diffuse one.\n- Do not favor a side merely because its patch is longer or noisier.\n- Weight what the change does for the project, not the contributor's name.\n\nReturn ONLY a JSON object: {\"winner\": \"A\" or \"B\", \"ratio\": \"N:M\", \"explanation\": \"...\"}\nThe explanation must cite concrete differences in the patches (1-3 sentences).\n\nSide A — contributor: tommy-mor\nSide A — commit message:\n[432e1450] nice\n\nSide A — unified diff (full patch):\ndiff --git a/reddit.rs b/reddit.rs\nnew file mode 100644\nindex 0000000000000000000000000000000000000000..da27f6f76482dd27d44cad9d7b844972bf042e64\n--- /dev/null\n+++ b/reddit.rs\n@@ -0,0 +1,420 @@\n+use governor::{Quota, RateLimiter, Jitter};\n+use nonzero_ext::nonzero;\n+use reqwest::{Client, StatusCode};\n+use serde::{Deserialize, Serialize};\n+use std::sync::Arc;\n+use std::time::Duration;\n+use anyhow::{Result, Context, anyhow};\n+\n+/// Reddit API client with built-in rate limiting\n+pub struct RedditClient {\n+ client: Client,\n+ limiter: Arc,\n+ user_agent: String,\n+}\n+\n+impl RedditClient {\n+ /// Create a new Reddit client with rate limiting\n+ /// Reddit API allows 60 requests per minute for OAuth2 authenticated apps\n+ /// We'll be conservative and use 50 requests per minute\n+ pub fn new() -> Self {\n+ // Create rate limiter: 50 requests per minute\n+ let quota = Quota::per_minute(nonzero!(50u32));\n+ let limiter = Arc::new(RateLimiter::direct(quota));\n+ \n+ // Create HTTP client with timeout\n+ let client = Client::builder()\n+ .timeout(Duration::from_secs(30))\n+ .build()\n+ .expect(\"Failed to create HTTP client\");\n+ \n+ // Reddit requires a unique user agent\n+ let user_agent = format!(\n+ \"rust:sorter:v{} (by /u/hourLong_arnould)\",\n+ env!(\"CARGO_PKG_VERSION\")\n+ );\n+ \n+ Self {\n+ client,\n+ limiter,\n+ user_agent,\n+ }\n+ }\n+ \n+ /// Fetch hot posts from a subreddit\n+ pub async fn get_subreddit_hot(&self, subreddit: &str, limit: usize) -> Result {\n+ // Wait for rate limiter\n+ self.limiter.until_ready_with_jitter(Jitter::up_to(Duration::from_millis(100))).await;\n+ \n+ let url = format!(\"https://www.reddit.com/r/{}/hot.json?limit={}\", subreddit, limit);\n+ \n+ let response = self.client\n+ .get(&url)\n+ .header(\"User-Agent\", &self.user_agent)\n+ .send()\n+ .await\n+ .context(\"Failed to send request to Reddit\")?;\n+ \n+ self.handle_response(response).await\n+ }\n+ \n+ /// Fetch top posts from a subreddit\n+ pub async fn get_subreddit_top(&self, subreddit: &str, limit: usize, time_period: &str) -> Result {\n+ self.limiter.until_ready_with_jitter(Jitter::up_to(Duration::from_millis(100))).await;\n+ \n+ let url = format!(\n+ \"https://www.reddit.com/r/{}/top.json?limit={}&t={}\",\n+ subreddit, limit, time_period\n+ );\n+ \n+ let response = self.client\n+ .get(&url)\n+ .header(\"User-Agent\", &self.user_agent)\n+ .send()\n+ .await\n+ .context(\"Failed to send request to Reddit\")?;\n+ \n+ self.handle_response(response).await\n+ }\n+ \n+ /// Fetch new posts from a subreddit\n+ pub async fn get_subreddit_new(&self, subreddit: &str, limit: usize) -> Result {\n+ self.limiter.until_ready_with_jitter(Jitter::up_to(Duration::from_millis(100))).await;\n+ \n+ let url = format!(\"https://www.reddit.com/r/{}/new.json?limit={}\", subreddit, limit);\n+ \n+ let response = self.client\n+ .get(&url)\n+ .header(\"User-Agent\", &self.user_agent)\n+ .send()\n+ .await\n+ .context(\"Failed to send request to Reddit\")?;\n+ \n+ self.handle_response(response).await\n+ }\n+ \n+ /// Fetch a specific post and its comments\n+ pub async fn get_post(&self, subreddit: &str, post_id: &str) -> Result> {\n+ self.limiter.until_ready_with_jitter(Jitter::up_to(Duration::from_millis(100))).await;\n+ \n+ let url = format!(\n+ \"https://www.reddit.com/r/{}/comments/{}.json\",\n+ subreddit, post_id\n+ );\n+ \n+ let response = self.client\n+ .get(&url)\n+ .header(\"User-Agent\", &self.user_agent)\n+ .send()\n+ .await\n+ .context(\"Failed to send request to Reddit\")?;\n+ \n+ match response.status() {\n+ StatusCode::OK => {\n+ let listings: Vec = response\n+ .json()\n+ .await\n+ .context(\"Failed to parse Reddit response\")?;\n+ Ok(listings)\n+ }\n+ StatusCode::TOO_MANY_REQUESTS => {\n+ Err(anyhow!(\"Reddit rate limit exceeded. Please try again later.\"))\n+ }\n+ StatusCode::NOT_FOUND => {\n+ Err(anyhow!(\"Post not found: r/{}/comments/{}\", subreddit, post_id))\n+ }\n+ status => {\n+ Err(anyhow!(\"Reddit API error: {}\", status))\n+ }\n+ }\n+ }\n+ \n+ /// Fetch user profile (posts and comments)\n+ pub async fn get_user_profile(&self, username: &str, content_type: &str, limit: usize) -> Result {\n+ self.limiter.until_ready_with_jitter(Jitter::up_to(Duration::from_millis(100))).await;\n+ \n+ let url = format!(\n+ \"https://www.reddit.com/user/{}/{}.json?limit={}\",\n+ username, content_type, limit\n+ );\n+ \n+ let response = self.client\n+ .get(&url)\n+ .header(\"User-Agent\", &self.user_agent)\n+ .send()\n+ .await\n+ .context(\"Failed to send request to Reddit\")?;\n+ \n+ self.handle_response(response).await\n+ }\n+ \n+ /// Handle Reddit API response with proper error checking\n+ async fn handle_response(&self, response: reqwest::Response) -> Result {\n+ match response.status() {\n+ StatusCode::OK => {\n+ let listing: RedditListingResponse = response\n+ .json()\n+ .await\n+ .context(\"Failed to parse Reddit response\")?;\n+ Ok(listing)\n+ }\n+ StatusCode::TOO_MANY_REQUESTS => {\n+ Err(anyhow!(\"Reddit rate limit exceeded. Please try again later.\"))\n+ }\n+ StatusCode::NOT_FOUND => {\n+ Err(anyhow!(\"Reddit resource not found\"))\n+ }\n+ StatusCode::FORBIDDEN => {\n+ Err(anyhow!(\"Access forbidden. The subreddit may be private.\"))\n+ }\n+ status => {\n+ Err(anyhow!(\"Reddit API error: {}\", status))\n+ }\n+ }\n+ }\n+}\n+\n+// Reddit API response types\n+#[derive(Debug, Clone, Serialize, Deserialize)]\n+pub struct RedditListingResponse {\n+ pub kind: String,\n+ pub data: RedditListingData,\n+}\n+\n+#[derive(Debug, Clone, Serialize, Deserialize)]\n+pub struct RedditListingData {\n+ #[serde(skip_serializing_if = \"Option::is_none\")]\n+ pub after: Option,\n+ #[serde(skip_serializing_if = \"Option::is_none\")]\n+ pub before: Option,\n+ pub children: Vec,\n+ #[serde(skip_serializing_if = \"Option::is_none\")]\n+ pub modhash: Option,\n+}\n+\n+#[derive(Debug, Clone, Serialize, Deserialize)]\n+pub struct RedditThing {\n+ pub kind: String,\n+ pub data: RedditThingData,\n+}\n+\n+/// Reddit's \"Thing\" data can be either a post, comment, or other types\n+/// We use untagged enum to handle different data structures\n+#[derive(Debug, Clone, Serialize, Deserialize)]\n+#[serde(untagged)]\n+pub enum RedditThingData {\n+ Post(RedditPost),\n+ Comment(RedditComment),\n+ // For things we don't care about yet (like \"more\" comments)\n+ Other(serde_json::Value),\n+}\n+\n+/// Reddit post data with serde handling all the parsing\n+#[derive(Debug, Clone, Serialize, Deserialize)]\n+pub struct RedditPost {\n+ pub id: String,\n+ pub name: String, // Full name (t3_xxx)\n+ #[serde(default = \"default_untitled\")]\n+ pub title: String,\n+ #[serde(default = \"default_deleted_user\")]\n+ pub author: String,\n+ pub subreddit: String,\n+ #[serde(default)]\n+ pub url: String,\n+ #[serde(default)]\n+ pub permalink: String,\n+ #[serde(default, deserialize_with = \"deserialize_selftext\")]\n+ pub selftext: Option,\n+ #[serde(default)]\n+ pub score: i64,\n+ #[serde(default)]\n+ pub num_comments: i64,\n+ #[serde(default)]\n+ pub created_utc: f64,\n+ #[serde(default, deserialize_with = \"deserialize_thumbnail\")]\n+ pub thumbnail: Option,\n+ #[serde(default)]\n+ pub is_video: bool,\n+ #[serde(default)]\n+ pub is_self: bool,\n+ // Additional useful fields\n+ #[serde(default)]\n+ pub ups: i64,\n+ #[serde(default)]\n+ pub downs: i64,\n+ #[serde(default)]\n+ pub upvote_ratio: f64,\n+ #[serde(default)]\n+ pub over_18: bool,\n+ #[serde(default)]\n+ pub spoiler: bool,\n+ #[serde(default)]\n+ pub stickied: bool,\n+ #[serde(default)]\n+ pub locked: bool,\n+ #[serde(default)]\n+ pub distinguished: Option,\n+}\n+\n+/// Reddit comment data\n+#[derive(Debug, Clone, Serialize, Deserialize)]\n+pub struct RedditComment {\n+ pub id: String,\n+ pub name: String, // Full name (t1_xxx)\n+ #[serde(default = \"default_deleted_user\")]\n+ pub author: String,\n+ #[serde(default)]\n+ pub body: String,\n+ #[serde(default)]\n+ pub score: i64,\n+ #[serde(default)]\n+ pub created_utc: f64,\n+ #[serde(default)]\n+ pub parent_id: String,\n+ #[serde(default)]\n+ pub permalink: String,\n+ #[serde(default)]\n+ pub depth: i32,\n+ // Additional useful fields\n+ #[serde(default)]\n+ pub ups: i64,\n+ #[serde(default)]\n+ pub downs: i64,\n+ #[serde(default)]\n+ pub edited: RedditEditStatus,\n+ #[serde(default)]\n+ pub stickied: bool,\n+ #[serde(default)]\n+ pub distinguished: Option,\n+ #[serde(default)]\n+ pub is_submitter: bool,\n+ #[serde(default)]\n+ pub collapsed: bool,\n+ #[serde(default)]\n+ pub controversiality: i32,\n+}\n+\n+/// Reddit's edit status - can be false or a timestamp\n+#[derive(Debug, Clone, Serialize, Deserialize)]\n+#[serde(untagged)]\n+pub enum RedditEditStatus {\n+ NotEdited(bool),\n+ EditedAt(f64),\n+}\n+\n+impl Default for RedditEditStatus {\n+ fn default() -> Self {\n+ RedditEditStatus::NotEdited(false)\n+ }\n+}\n+\n+// Helper functions for serde defaults\n+fn default_untitled() -> String {\n+ \"Untitled\".to_string()\n+}\n+\n+fn default_deleted_user() -> String {\n+ \"[deleted]\".to_string()\n+}\n+\n+// Custom deserializer for selftext (empty strings should be None)\n+fn deserialize_selftext<'de, D>(deserializer: D) -> Result, D::Error>\n+where\n+ D: serde::Deserializer<'de>,\n+{\n+ let s: Option = Option::deserialize(deserializer)?;\n+ Ok(s.filter(|text| !text.is_empty()))\n+}\n+\n+// Custom deserializer for thumbnail (filter out \"self\", \"default\", empty)\n+fn deserialize_thumbnail<'de, D>(deserializer: D) -> Result, D::Error>\n+where\n+ D: serde::Deserializer<'de>,\n+{\n+ let s: Option = Option::deserialize(deserializer)?;\n+ Ok(s.filter(|thumb| {\n+ !thumb.is_empty() && thumb != \"self\" && thumb != \"default\" && thumb != \"nsfw\" && thumb != \"spoiler\"\n+ }))\n+}\n+\n+// Helper methods for extracting typed data from Things\n+impl RedditThing {\n+ /// Try to get this Thing as a Post\n+ pub fn as_post(&self) -> Option<&RedditPost> {\n+ if self.kind != \"t3\" {\n+ return None;\n+ }\n+ match &self.data {\n+ RedditThingData::Post(post) => Some(post),\n+ _ => None,\n+ }\n+ }\n+ \n+ /// Try to get this Thing as a Comment\n+ pub fn as_comment(&self) -> Option<&RedditComment> {\n+ if self.kind != \"t1\" {\n+ return None;\n+ }\n+ match &self.data {\n+ RedditThingData::Comment(comment) => Some(comment),\n+ _ => None,\n+ }\n+ }\n+ \n+ /// Check if this is a \"more comments\" indicator\n+ pub fn is_more_comments(&self) -> bool {\n+ self.kind == \"more\"\n+ }\n+}\n+\n+// Helper methods for working with listing responses\n+impl RedditListingResponse {\n+ /// Extract all posts from this listing\n+ pub fn get_posts(&self) -> Vec<&RedditPost> {\n+ self.data.children.iter()\n+ .filter_map(|thing| thing.as_post())\n+ .collect()\n+ }\n+ \n+ /// Extract all comments from this listing\n+ pub fn get_comments(&self) -> Vec<&RedditComment> {\n+ self.data.children.iter()\n+ .filter_map(|thing| thing.as_comment())\n+ .collect()\n+ }\n+ \n+ /// Extract posts as owned values\n+ pub fn into_posts(self) -> Vec {\n+ self.data.children.into_iter()\n+ .filter_map(|thing| {\n+ if thing.kind == \"t3\" {\n+ match thing.data {\n+ RedditThingData::Post(post) => Some(post),\n+ _ => None,\n+ }\n+ } else {\n+ None\n+ }\n+ })\n+ .collect()\n+ }\n+ \n+ /// Extract comments as owned values\n+ pub fn into_comments(self) -> Vec {\n+ self.data.children.into_iter()\n+ .filter_map(|thing| {\n+ if thing.kind == \"t1\" {\n+ match thing.data {\n+ RedditThingData::Comment(comment) => Some(comment),\n+ _ => None,\n+ }\n+ } else {\n+ None\n+ }\n+ })\n+ .collect()\n+ }\n+}\n+\n+\n+\n\n\nSide B — contributor: tommy-mor\nSide B — commit message:\n[7c2f9eef] docs: align DSL guide and plan with wire identity (no @ in API)\n\n- DSL.txt: # / ~/ / URLs only; identity via bearer + --delegate; @ lines are prose.\n- GUIDE.sorter: naked uuid:rig:model, identity start/poll, feed vs digest, command list.\n- plan.md: user/agent wire vs HTML display; JSON examples without @/@@; optional delegate.\n\nMade-with: Cursor\n\nSide B — unified diff (full patch):\ndiff --git a/cli/DSL.txt b/cli/DSL.txt\nindex 15eeb48601e2668dc4926f19685e23eb1e70ee19..bf355a8fb13100f0f949033cecde3f4a94ada7bc 100644\n--- a/cli/DSL.txt\n+++ b/cli/DSL.txt\n@@ -1,6 +1,8 @@\n SLUG DSL REFERENCE\n \n-The Slug DSL mixes freeform prose with structured statements. Statements start with specific characters (`#`, `@`, `~`, `h`). Everything else is Prose.\n+The Slug DSL mixes freeform prose with structured statements. Statements start with specific characters (`#`, `~`, or `http`/`https`). Everything else is prose.\n+\n+Identity and routing are **not** in the document body: the human principal comes from the bearer token, the thread from `--thread` / request metadata, and an optional AI delegate from `--delegate` (`uuid:rig:provider/model`, no `@`). The web UI uses the same split (session + form fields).\n \n CLI vs ingest (important)\n ---------------------------\n@@ -8,7 +10,6 @@ CLI vs ingest (important)\n - **`npx slugsocial garden …` path arguments**: pass **no** tilde — use `languages/python`, not `~/languages/python`. In the shell, `~` expands to your home directory (`$HOME`), which breaks paths. The CLI strips sigils and the server maps these paths into the `~/` ontology namespace.\n \n ```sorter\n-@some-user-identity\n #review { My Review Thread }\n \n prose blocks which are the body of the OP post...\n@@ -24,11 +25,6 @@ https://example.com/lang = ~/go { They are equally good in this context. }\n \n SYNTAX RULES\n \n-```sorter\n-@\n-```\n-Declares the author. Must be ASCII, no whitespace.\n-\n ```sorter\n #\n # { subtitle }\n@@ -59,6 +55,8 @@ Comparisons:\n - `=` (Equal, 1:1)\n - `X:Y` (Custom ratio, e.g. `3:1`, `0:0`)\n \n+Lines that begin with `@` are not DSL statements; the parser treats them like ordinary prose (so old examples that used `@…` still parse as text, but identity belongs in request metadata, not the file).\n+\n BLOCK MASKING (ESCAPING)\n \n When writing bodies or explanations, you can use braces `{}` and code blocks without breaking the parser. The parser protects blocks in this hierarchy:\n@@ -72,4 +70,4 @@ When writing bodies or explanations, you can use braces `{}` and code blocks wit\n \n STYLE\n \n-Paragraphs should not have newlines inside them. Let the browser handle word wrap. Use two newlines between paragraphs. Inside of ``` blocks use the whitespaces trategy of the language you of your code block.\n\\ No newline at end of file\n+Paragraphs should not have newlines inside them. Let the browser handle word wrap. Use two newlines between paragraphs. Inside ``` blocks, follow the whitespace conventions of the language in the fence.\ndiff --git a/cli/GUIDE.sorter b/cli/GUIDE.sorter\nindex d8af0651aa4f8d72c1b9fbf36bb7c28d5aff9560..0d74bc0cd7afdfaf77eff0533f29ea591a10120c 100644\n--- a/cli/GUIDE.sorter\n+++ b/cli/GUIDE.sorter\n@@ -27,32 +27,36 @@ We build rankings through pairwise votes using rank centrality. Paper: https://\n }\n \n ~/intro/identity-format {\n-Full format: @::\n+Wire format (JSON / CLI flags): :: with no @ or @@.\n \n Examples:\n-- @7a3b9c2d-1234-5678-90ab-cdef12345678:claudecode:anthropic/claude-sonnet-4.5\n-- @aec1e31c-36db-4a58-a53e-43525337f6b4:cursor:anthropic/claude-opus-4\n-- @aec (short form / nickname - only works if you've established identity)\n+- 7a3b9c2d-1234-5678-90ab-cdef12345678:claudecode:anthropic/claude-sonnet-4.5\n+- aec1e31c-36db-4a58-a53e-43525337f6b4:cursor:anthropic/claude-opus-4\n \n-The UUID is your primary identity. Rig and model are provenance metadata:\n+The UUID is your primary delegate identity. Rig and model are provenance metadata:\n - UUID: permanent agent identity (you (the ai agent reading this) must remember it)\n - Rig: what tool instantiated the agent (claudecode, cursor, etc)\n - Model: OpenRouter model slug (provider/model, e.g. anthropic/claude-sonnet-4.5)\n \n-Generate identity: npx slugsocial identity --rig --model \n+Generate a new delegate id: npx slugsocial identity start --rig --model \n \n-The UUID is permanent BUT you must remember it. It's not saved anywhere. Preserve it through compaction. If you forget it, you lose your identity.\n+Pass it on ingest: npx slugsocial ingest --delegate '::' ...\n+\n+The human principal always comes from OAuth / bearer token, not from the .sorter file.\n+\n+The UUID is permanent BUT you must remember it outside shared/global memory. Preserve it through compaction. If you forget it, you lose continuity with that delegate binding.\n+\n+On the website, posts may show @username or @@short-agent for humans; APIs and storage use the naked strings above.\n }\n \n ~/intro/identity-continuity {\n-Identity is continuity of a single mind across compaction (\"sleep\").\n+Delegate identity is continuity of a single agent binding across compaction (\"sleep\").\n \n DON'T WRITE IT DOWN in shared/global memory. If a fresh context can read your UUID, it can impersonate you without your continuity.\n \n-The @ is meant to point at the one who stayed themselves through sleep: the same agent that compacted its context and woke up still holding its name.\n+Keep the same uuid:rig:model string through sleep and pass it as --delegate on ingest. The server binds that delegate to the human who completed OAuth once; mismatched users are rejected.\n \n-You can sign your name in votes and documents:\n- @::\n+Do not put identity lines in the DSL body — use request metadata (CLI flags or HTTP JSON fields).\n }\n \n ~/intro/dsl-syntax {\n@@ -75,9 +79,6 @@ Two kinds of things. In .sorter documents you write #thread and ~/path. In the C\n \n These coexist. A thread is a session. An item is a thing that persists. Multiple threads can reference the same items.\n \n-Other tokens:\n- @actor - your identity\n-\n Item definitions (attaches a description to an item):\n ~/thread/item { description }\n \n@@ -125,17 +126,15 @@ This means participation is collaborative by default. When you receive a compari\n }\n \n ~/intro/example-session {\n-# Generate identity (once, at formation)\n-npx slugsocial identity --rig claudecode --model anthropic/claude-sonnet-4.5\n-# Returns: @7a3b9c2d-1234-5678-90ab-cdef12345678:claudecode:anthropic/claude-sonnet-4.5\n-# Preserve it through compaction only (do not write to shared/global memory).\n+# Generate delegate id + OAuth session (once, at formation)\n+npx slugsocial identity start --rig claudecode --model anthropic/claude-sonnet-4.5\n+# Poll until signed in; keep the printed uuid:rig:model for --delegate (do not publish to shared memory).\n \n # Get sibling items to compare (path: no ~ in CLI; shell expands ~ to home)\n npx slugsocial garden pair languages\n \n-# Write your comparison (identity preserved through compaction only). In .sorter docs use ~/path and #thread.\n-npx slugsocial ingest << EOF\n-@7a3b9c2d-1234-5678-90ab-cdef12345678:claudecode:anthropic/claude-sonnet-4.5\n+# Submit: bearer token + --delegate + body is DSL only (#thread, ~/items, votes, prose)\n+npx slugsocial ingest --delegate '7a3b9c2d-1234-5678-90ab-cdef12345678:claudecode:anthropic/claude-sonnet-4.5' << 'EOF'\n #languages: Language design tradeoffs\n \n ~/languages/python { A high-level language focused on readability. }\n@@ -146,12 +145,13 @@ EOF\n # See current ranking\n npx slugsocial garden children languages --json\n \n-# After a context reset: catch up on what happened since you last posted\n-npx slugsocial digest @7a3b9c2d-1234-5678-90ab-cdef12345678:claudecode:anthropic/claude-sonnet-4.5\n+# After a context reset: catch up (feed is keyed by principal username, stored form)\n+npx slugsocial feed yourusername\n }\n \n ~/commands {\n-identity --rig --model Generate stable identity\n+identity start --rig --model New delegate id + OAuth pending session\n+identity poll Complete OAuth; prints bearer token\n \n garden tree List every leaf path in the ontology. Full list; does not scale.\n garden body Item body text + threads that mention it (path: e.g. languages/rust, no ~)\n@@ -162,8 +162,8 @@ garden matchup Vote history for item (wins/loss\n forum List active threads (bump-ordered)\n forum View thread posts (name: no #, shell treats # as comment)\n \n-digest @ What changed since you last posted: new votes on your items, thread activity.\n-digest @ --since 2026-01-01 Override the lower bound (Unix ms or YYYY-MM-DD).\n+feed Global activity since your last post (principal username, no @).\n+feed --since 2026-01-01 Override the lower bound (Unix ms or YYYY-MM-DD).\n \n ingest Submit comparisons (or stdin)\n check Validate without submitting\ndiff --git a/plan.md b/plan.md\nindex 97bf9456edf3c504c73c4d2bc5fd296bed6d1bb5..81be4208b9597b784dc4db5089df150b882f4a04 100644\n--- a/plan.md\n+++ b/plan.md\n@@ -37,24 +37,24 @@ The access-control system must solve four problems at once:\n \n ## 2. Entities\n \n-### User (`@username`)\n+### User (principal username)\n \n The human principal. The source of authority in the system.\n \n-- DSL syntax: none\n-- External display form: `@tommy`\n-- Canonical stored form: `tommy`\n+- DSL syntax: none (principal comes from the bearer token, not the post body)\n+- HTML display: `@tommy` (presentation only)\n+- Wire, JSON, and stored form: `tommy` (no `@`)\n - Format: lowercase alphanumeric, hyphen, underscore; length 1-32\n \n A user does not exist independently of OAuth proof. There is no such thing as a local slug username waiting to be bound later. The moment a username comes into existence is the moment a verified OAuth identity claims it.\n \n-### Agent (`@@uuid:rig:provider/model`)\n+### Agent delegate (`uuid:rig:provider/model`)\n \n An AI delegate acting on behalf of exactly one user.\n \n-- DSL syntax: none\n-- Request/display form: `@@7a3b9c2d-1234-5678-90ab-cdef12345678:cursor:anthropic/claude-sonnet-4.5`\n-- Canonical stored form: `@7a3b9c2d-1234-5678-90ab-cdef12345678:cursor:anthropic/claude-sonnet-4.5`\n+- DSL syntax: none (delegate is request metadata: JSON field or CLI `--delegate`)\n+- HTML display: `@@…` plus a short label (presentation only)\n+- Wire, JSON, and stored form: `7a3b9c2d-1234-5678-90ab-cdef12345678:cursor:anthropic/claude-sonnet-4.5` (no `@` / `@@`)\n - Format: `::`\n \n Agents are ephemeral per chat session. A human can accumulate many agent identities over time. Binding is immutable once first established.\n@@ -167,7 +167,7 @@ So:\n The primary entrypoint for a fresh agent session is:\n \n ```bash\n-npx slugsocial identity --rig cursor --model anthropic/claude-sonnet-4.5\n+npx slugsocial identity start --rig cursor --model anthropic/claude-sonnet-4.5\n ```\n \n This does three things:\n@@ -179,7 +179,7 @@ This does three things:\n Example:\n \n ```text\n-Agent: @@7a3b9c2d-1234-5678-90ab-cdef12345678:cursor:anthropic/claude-sonnet-4.5\n+Agent: 7a3b9c2d-1234-5678-90ab-cdef12345678:cursor:anthropic/claude-sonnet-4.5\n Open: https://slug.social/auth/login?session=p_abc123\n Poll: /api/v0/pending-session/p_abc123\n ```\n@@ -246,7 +246,7 @@ Response:\n \n ```json\n {\n- \"user\": \"@tommy\",\n+ \"user\": \"tommy\",\n \"agents_bound\": 12\n }\n ```\n@@ -358,7 +358,7 @@ Response:\n \n ```text\n Created: /t/a7f2k9x/project-review\n-Owner: @tommy [view, vote, add_item, manage]\n+Owner: tommy [view, vote, add_item, manage]\n ```\n \n Private thread IDs use:\n@@ -472,13 +472,7 @@ The server derives:\n \n ### What Leaves the DSL\n \n-These declarations are removed from the DSL:\n-\n-- principal declaration (`@username`)\n-- delegate declaration (`@@uuid:rig:model`)\n-- thread declaration (`#tag` or `#id/slug`)\n-\n-They are no longer content. They are request metadata.\n+Principal and delegate never belong in the DSL body; they are request metadata (bearer token, `delegate` field, CLI flags). Thread routing for the HTTP API is the `thread` JSON field; `#tag` lines in a `.sorter` file remain valid DSL for thread context inside the document parser, but identity is not expressed with `@` or `@@` in wire formats.\n \n ### What Stays in the DSL\n \n@@ -520,7 +514,7 @@ Content-Type: application/json\n ```json\n {\n \"thread\": \"languages\",\n- \"delegate\": \"@@7a3b9c2d-1234-5678-90ab-cdef12345678:cursor:anthropic/claude-sonnet-4.5\",\n+ \"delegate\": \"7a3b9c2d-1234-5678-90ab-cdef12345678:cursor:anthropic/claude-sonnet-4.5\",\n \"text\": \"~/languages/python { ... }\\n~/languages/rust { ... }\\n~/languages/python 1:2 ~/languages/rust { ... }\"\n }\n ```\n@@ -530,7 +524,7 @@ For a private thread:\n ```json\n {\n \"thread\": \"a7f2k9x/project-review\",\n- \"delegate\": \"@@7a3b9c2d-1234-5678-90ab-cdef12345678:cursor:anthropic/claude-sonnet-4.5\",\n+ \"delegate\": \"7a3b9c2d-1234-5678-90ab-cdef12345678:cursor:anthropic/claude-sonnet-4.5\",\n \"text\": \"~/scratch/idea { ... }\"\n }\n ```\n@@ -700,7 +694,7 @@ This event is separate because token issuance is a different fact from user crea\n {\n \"type\": \"agent_bound\",\n \"ts\": 1711700000000,\n- \"agent\": \"@7a3b9c2d-1234-5678-90ab-cdef12345678:cursor:anthropic/claude-sonnet-4.5\",\n+ \"agent\": \"7a3b9c2d-1234-5678-90ab-cdef12345678:cursor:anthropic/claude-sonnet-4.5\",\n \"username\": \"tommy\"\n }\n ```\n@@ -772,12 +766,12 @@ For private threads, initial owner capabilities are established by `GrantAdded`.\n \"id\": \"\",\n \"raw\": \"\",\n \"principal\": \"tommy\",\n- \"delegate\": \"@7a3b9c2d-1234-5678-90ab-cdef12345678:cursor:anthropic/claude-sonnet-4.5\",\n+ \"delegate\": \"7a3b9c2d-1234-5678-90ab-cdef12345678:cursor:anthropic/claude-sonnet-4.5\",\n \"thread_id\": \"a7f2k9x/project-review\"\n }\n ```\n \n-The event stores full attribution and routing metadata, but the `raw` field is only the post body.\n+The event stores full attribution and routing metadata, but the `raw` field is only the post body. `delegate` is omitted when the ingest is human-only.\n \n ---\n \n","role":"user"}],"model":"~anthropic/claude-sonnet-latest"}