Artifact handoff
Move bounded, verified file-backed output between application integrations.
Cross-application work needs an explicit transfer boundary. artifact.handoff is a broker-owned primitive for copying a bounded binary file from an authorized producer location to an authorized recipient location.
- ProduceExport a file from the source application.
- HandoffCheck bytes, digest and authorized paths.
- ImportUse the recipient's native import operation.
- Read backInspect what the recipient actually accepted.
On Linux, an explicit overwrite: false requests atomic no-replace publication. An existing destination returns a conflict without replacing it. Unsupported backends refuse this mode without write I/O. Omitting the flag preserves the default replacement behavior.
Discover both ends
Section titled “Discover both ends”Discover the producer and consumer capabilities separately. Artifact tags describe semantic compatibility; they do not create filesystem grants or prove every native file format is accepted. Check the concrete media type and the recipient’s documented import surface.
For example, moving a mesh into a game involves two application operations as well as a transfer. The modeling application exports a supported file, the broker hands off the bounded file, and the game integration imports it. Each boundary needs its own authorization and evidence. Tideling records a historical Blender-to-Godot example with its own frozen source revision.
Verify the transfer
Section titled “Verify the transfer”The documented handoff validates the producer path, expected bytes and digest, recipient scope and transfer limits. The v1 file-backed ceiling is 64 MiB. Larger media requires a future streaming transport; this website does not imply an unlimited copy service.
Keep driver tokens distinct from paths
Section titled “Keep driver tokens distinct from paths”Figma exports can remain behind authenticated driver-local artifact tokens and bounded chunk reads. Those opaque tokens are not filesystem paths. File-backed handoff does not treat a Figma token as an arbitrary file the broker can copy.
A transferred file proves matching transferred bytes. It does not prove the consumer imported it correctly; use fresh native readback and Effects where that integration supports them.
| Evidence | What it establishes |
|---|---|
| A producer export result | What the producer reported creating |
| Matching bytes and digest at handoff | The bounded file was transferred intact |
| Fresh native consumer readback | What the recipient imported or changed, within the observed scope |
Keep these checks separate. A successful copy cannot stand in for a successful import, and a rendered preview cannot establish every property of the native scene.
Source: cross-driver artifact handoff contract, source references checked 7 October 2026.