Skip to content

Site manifest

The manifest is a JSON file at /.well-known/wall.json. It is how a Level 2 site tells a program where its feeds are and what the wall may do. A program also finds it through <link rel="wall-manifest" href="/.well-known/wall.json">, and checks the well-known path even when the <link> is missing. URLs in the manifest are absolute or relative to the manifest URL. The JSON Schema is manifest.schema.json.

{
"version": 1,
"policy": "allow",
"name": "Example",
"brand": { "accent": "#c9334f", "logo": "/logo-512.png", "bg": "#0e0e10" },
"feeds": [
{ "id": "latest", "title": "Latest", "url": "/wall/feed?sort=new", "cursor": true },
{ "id": "popular", "title": "Popular", "url": "/wall/feed?sort=popular", "cursor": true },
{ "id": "search", "type": "search", "url": "/wall/feed?q={query}" }
],
"filters": [ { "id": "type", "title": "Type", "values": ["all", "photo", "video"], "param": "type" } ],
"media": {
"hosts": ["cdn.example.com"],
"variants": { "thumb": 512, "focus": 1024, "full": 2560 },
"projections": ["flat", "equirect180"]
},
"actions": {
"like": { "method": "POST", "url": "/api/items/{id}/like", "auth": "session", "toggle": true },
"cart": { "mode": "deeplink", "url": "/cart/add/{id}" }
},
"auth": { "login": "/login", "device_link": "/wall/link" },
"recipe": "/.well-known/wall-recipe.json",
"embed": { "route": "/xr" }
}
FieldMeaning
versionInteger, 1. Required.
policyallow (the default), deny (programs must not build a wall for this origin) or recipes-only (only the recipe you publish in recipe may be used).
nameThe name of the site. Shown in texts such as the sign-in notice.
brandaccent, logo and bg. The wall uses them for its own colours and logo.
feedsRequired, at least one. A feed with "type": "search" has {query} in its URL and is used for search. Every other feed is a browsable list. See Feeds.
filtersEach filter has an id, a display title, its values and the query param it is sent in. The value all means no filter: the parameter is left out.
media.hostsHosts that serve images and video with Access-Control-Allow-Origin: * (or the requesting origin). See Troubleshooting.
media.projectionsVideo projections that appear in the feed. Absent means flat only.
media.resizeRules that turn an image URL into smaller copies. See Image sizes.
actionsButtons that send a request or open a page. See Actions and login.
authlogin (your sign-in page), device_link (the phone sign-in endpoint) and csrf.
recipeYour own recipe for your DOM. See Recipes.
viewHow the wall looks. See View customization.
embed.routeWhere your own Level 3 wall lives.

brand.accent should have a contrast of at least 4.5:1 against white. The validator checks it.

{ "version": 1, "policy": "deny", "feeds": [{ "id": "x", "url": "/x" }] }

With policy: "deny", WellKnownAdapter makes page() reject with an AdapterError whose code is policy-denied, and the embed script stops. See Security and privacy.