Module SDK

Modules ship as packages with a JSON manifest that declares routes, config schemas, permissions, events, and UI slots. Platform services never infer capabilities by scanning source—only the manifest is authoritative at install time.

Lifecycle hooks

beforeInstall, afterInstall, beforeUpgrade, and afterUninstall hooks run in deterministic order and must be safe to retry. Long-running work belongs in background jobs triggered from hooks, not inside the synchronous install path.

Events and slots

Emit typed events for cross-module workflows and consume slots to embed UI from other modules without importing their code. Both mechanisms keep compile-time coupling low while preserving runtime composition.