Tool Contract v2.0 · five federated tools Contrato de Herramientas v2.0 · cinco herramientas federadas

One identity.
A contract every tool keeps.
Una identidad.
Un contrato que toda herramienta cumple.

BitBot issues the tokens, owns the project registry, and holds every tool to a written specification. Your agents authenticate once and work across deployment, knowledge, tasks, testing and browser automation with one project context. BitBot emite los tokens, es dueño del registro de proyectos y somete a cada herramienta a una especificación escrita. Tus agentes se autentican una vez y trabajan sobre despliegue, conocimiento, tareas, pruebas y automatización de navegador con un solo contexto de proyecto.

Every claim on this page is paired with the traffic that proves it. Cada afirmación en esta página va junto al tráfico que la comprueba.

collector → tool

            

What it isQué es

The hub your tools answer to El hub al que responden tus herramientas

Nothing federates itself. BitBot is the one place that knows who a user is, which projects exist, what each plan allows, and what every tool promised to serve. Nada se federa solo. BitBot es el único lugar que sabe quién es un usuario, qué proyectos existen, qué permite cada plan y qué prometió servir cada herramienta.

Identity, issued onceIdentidad, emitida una vez

BitBot signs RS256 tokens and publishes its JWKS. Tools verify locally — no callback per request, and no tool ever holds a user's password. BitBot firma tokens RS256 y publica su JWKS. Las herramientas verifican localmente — sin llamada por petición, y ninguna guarda la contraseña de nadie.

GET /.well-known/jwks.json "alg": "RS256", "kid": "bitbot-…"

One project, propagatedUn proyecto, propagado

A project is created in BitBot, then bootstrapped into every tool in precedence order. What one tool generates feeds the next — a deployment URL becomes the test suite's target without anyone retyping it. Un proyecto se crea en BitBot y luego se inicializa en cada herramienta por orden de precedencia. Lo que una genera alimenta a la siguiente — una URL de despliegue se vuelve el objetivo de las pruebas sin que nadie la reescriba.

POST /bitbot/project hasslefree (p:10) → contextbrain (p:20) letstask · detesting (p:50) → browse4me (p:100)

Limits live in one placeLos límites viven en un solo lugar

Plans are defined once and read by every tool. A tool asks what a project is allowed rather than inventing its own tiers. Los planes se definen una vez y los lee cada herramienta. Una herramienta pregunta qué tiene permitido un proyecto en lugar de inventar sus propios niveles.

GET /limits?project=acme { "plan": "pro", "limits": { … } }

Agents drive it over MCPLos agentes lo manejan por MCP

Claude Code and other MCP clients connect to every tool at once and to BitBot itself, which tracks the workflow and holds the project's shared pages. Claude Code y otros clientes MCP se conectan a todas las herramientas a la vez y a BitBot, que registra el workflow y guarda las páginas compartidas del proyecto.

bitbot_workflow_start · bitbot_workflow_advance bitbot_wiki_get · bitbot_wiki_write

FederationFederación

Five tools, one contextCinco herramientas, un contexto

Each is a full product in its own right. BitBot is what makes them one system: shared identity, shared project, and an ordering that lets output flow downstream. Cada una es un producto completo por sí sola. BitBot es lo que las vuelve un solo sistema: identidad compartida, proyecto compartido y un orden que deja fluir la salida de una hacia la siguiente.

HassleFree deploydesplegar

Kubernetes PaaS. Build plans, container builds, services, volumes, workflows and ephemeral environments. PaaS sobre Kubernetes. Build plans, imágenes, servicios, volúmenes, workflows y entornos efímeros.

precedence10
ContextBrain understandcomprender

Code graph and knowledge base. Symbol search, call hierarchies, architectural patterns, business rules and version-locked library docs. Grafo de código y base de conocimiento. Búsqueda de símbolos, jerarquías de llamadas, patrones, reglas de negocio y documentación fijada por versión.

precedence20
LetsTask planplanear

Work breakdown for agents: analyses split into implementations, features and tasks, with review sessions and evidence before anything closes. Descomposición del trabajo para agentes: análisis divididos en implementaciones, features y tareas, con sesiones de revisión y evidencia antes de cerrar.

precedence50
DeTesting verifyverificar

API and browser testing. Collections, environments, assertions, visual baselines, schedules and flaky-test analytics. Pruebas de API y de navegador. Colecciones, entornos, aserciones, líneas base visuales, calendarios y análisis de pruebas inestables.

precedence50
Browse4Me automateautomatizar

Browser automation with recording and replay, network capture, request interception and stealth mode for bot-protected sites. Automatización de navegador con grabación y reproducción, captura de red, intercepción de peticiones y modo sigiloso para sitios protegidos.

precedence100

The contractEl contrato

A specification, not an integration guide Una especificación, no una guía de integración

The Tool Contract is normative: where a tool, a plan or an implementation disagrees with it, the document wins. v2.0 exists so a machine can collect metrics that mean the same thing tomorrow as they do today. El Contrato de Herramientas es normativo: donde una herramienta, un plan o una implementación lo contradigan, gana el documento. v2.0 existe para que una máquina pueda recolectar métricas que signifiquen mañana lo mismo que hoy.

Reachable through any gateway Alcanzable por cualquier gateway §1.2

Gateways disagree about whether they strip /api, and none of them document it. A tool serves the contract router at both prefixes, so one path always works. Los gateways no se ponen de acuerdo sobre si quitan /api, y ninguno lo documenta. Una herramienta sirve el router del contrato en ambos prefijos, así que una ruta siempre funciona.

app.use('/bitbot', bitbotRoutes) app.use('/api/bitbot', bitbotRoutes)

A token for the collectorUn token para el recolector §2.2

An unattended collector has no user and owns no projects, so it carries a short-lived BitBot-signed token. Tools assert the signature, the issuer, the audience and the admin claim — never a shared secret. Un recolector desatendido no tiene usuario ni proyectos, así que lleva un token corto firmado por BitBot. Las herramientas verifican firma, emisor, audiencia y el claim admin — nunca un secreto compartido.

{ "type": "admin", "admin": true,   "aud": "bitbot-tools", "exp": now+300s }

Every metric explains itself Cada métrica se explica sola §3.6

A number without a definition is how two tools end up counting different things under the same label. Each stat carries prose stating what it includes and what it excludes. A stat without one is rejected. Un número sin definición es como dos herramientas terminan contando cosas distintas bajo la misma etiqueta. Cada estadística lleva una prosa que dice qué incluye y qué excluye. Si falta, se rechaza.

{ "key": "letstask.tasks.open",   "aggregation": "gauge", "window": null,   "definition": "Tasks in TODO or DOING…" }

A gap is never a zeroUn vacío nunca es un cero §3.7

A placeholder zero makes a quiet project look identical to a broken collector, and once written to an append-only series it can never be corrected. Tools omit what they cannot compute. Un cero de relleno hace que un proyecto tranquilo se vea igual que un recolector roto, y una vez escrito en una serie inmutable ya no se corrige. Las herramientas omiten lo que no pueden calcular.

// no runs in the window { "value": 0 } — indistinguishable stat omitted entirely

Compliance is measured, not claimed El cumplimiento se mide, no se declara §7.1

Reachability, auth and shape fail in ways that look identical from a single probe — a routing miss returns something shaped like an auth error. BitBot checks all three separately, and treats a 200 carrying HTML as the miss it is. Alcance, autenticación y forma fallan de maneras idénticas ante una sola sonda — un error de ruteo devuelve algo con forma de error de autenticación. BitBot revisa las tres por separado, y trata un 200 con HTML como el fallo que es.

reachable — contract error envelope authorized — system token accepted shaped — nine fields per stat

Pulse

Every tool's numbers, kept over time Los números de cada herramienta, guardados en el tiempo

An hourly collector polls every tool for every project it serves and appends what comes back to an immutable series. A failed poll writes nothing at all, so a quiet project stays distinguishable from an unreachable tool. Un recolector horario consulta a cada herramienta por cada proyecto que atiende y agrega lo que recibe a una serie inmutable. Una consulta fallida no escribe nada, así que un proyecto tranquilo sigue siendo distinguible de una herramienta caída.

Trend is the hub's jobLa tendencia es tarea del hub

A tool sees one moment and cannot know its own direction of travel, so it never sends a trend. BitBot computes the delta against the newest sample a full window old — an hour-over-hour change on a weekly counter is noise, not signal. Una herramienta ve un instante y no puede saber su propia dirección, así que nunca envía tendencia. BitBot calcula el delta contra la muestra más reciente con una ventana completa de antigüedad — un cambio hora a hora sobre un contador semanal es ruido, no señal.

hasslefree.builds.failed P7D 7 ↑ +3 vs 24h ago

Definitions travel with the dataLas definiciones viajan con el dato

Each stored sample keeps the definition it was published with. When a tool changes what a key measures, the shift is visible in the history instead of quietly rewriting the past. Cada muestra guarda la definición con la que se publicó. Cuando una herramienta cambia lo que mide una clave, el cambio se ve en el historial en vez de reescribir el pasado en silencio.

GET /projects/acme/pulse/series?key=… { "definitionChanged": true }

Wiki

A shared space agents can write to Un espacio compartido donde los agentes escriben

Runbooks, decisions and conventions live with the project, and an agent can keep them current. Pages are readable by project members only — an agent cannot tell whether the block it just pasted came from a private repo or a log. Runbooks, decisiones y convenciones viven con el proyecto, y un agente puede mantenerlos al día. Las páginas solo las leen los miembros del proyecto — un agente no puede saber si el bloque que acaba de pegar vino de un repo privado o de un log.

No blind overwritesSin sobrescrituras a ciegas

Editing a page requires the version you read. An agent that tries to replace prose it never fetched is refused and told the current version, which turns the likeliest failure into a mechanical retry. Editar una página exige la versión que leíste. Un agente que intente reemplazar texto que nunca obtuvo es rechazado y recibe la versión actual, lo que convierte el fallo más probable en un reintento mecánico.

PUT /projects/acme/wiki/runbook 409 "VERSION_REQUIRED", "currentVersion": 4

Every version, every authorCada versión, cada autor

Agents rewrite prose wholesale rather than editing a line, so every version is kept and attributed — to a member, or to the tool that wrote it. Los agentes reescriben el texto completo en vez de editar una línea, así que cada versión se guarda y se atribuye — a un miembro, o a la herramienta que la escribió.

v4 · letstask · "recorded rollback steps" v3 · member · "fixed the port"

WorkflowsWorkflows

A request, tracked through seven phases Una petición, seguida por siete fases

An agent starts a workflow with a plain request. BitBot queues it per project and records each phase, the files touched, the test runs and the result — so a session that ends mid-task can be picked up rather than restarted. Un agente inicia un workflow con una petición en lenguaje natural. BitBot lo encola por proyecto y registra cada fase, los archivos tocados, las pruebas y el resultado — así una sesión que termina a medias se retoma en vez de reiniciarse.

01 CONTEXT 02 ANALYSIS 03 REVIEW 04 IMPLEMENTATION 05 TESTING 06 PR_CREATION 07 KNOWLEDGE

SecuritySeguridad

Five credentials, each with a job Cinco credenciales, cada una con su función

Audience alone is not identity. Every token carries a type claim, and a verifier that stops at the signature accepts the wrong caller. La audiencia por sí sola no es identidad. Cada token lleva un claim type, y un verificador que se detiene en la firma acepta al interlocutor equivocado.

CredentialCredencial Carried byLo usa ReachesAlcanza
type: access A person, after login or device flowUna persona, tras login o device flow Their own projectsSus propios proyectos
type: user A person, inside a tool's own UIUna persona, dentro de la UI de una herramienta That tool, as themselvesEsa herramienta, como ella misma
type: admin BitBot's collector, unattendedEl recolector de BitBot, desatendido Aggregate reads only — never a mutation, never record-level contentSolo lecturas agregadas — nunca una mutación ni contenido a nivel de registro
proj_… A tool acting for one projectUna herramienta actuando por un proyecto That project, in that toolEse proyecto, en esa herramienta
x-tool-key A registered tool calling BitBotUna herramienta registrada llamando a BitBot Limits and project syncLímites y sincronización de proyectos

StartEmpezar

Four commands to a working project Cuatro comandos hasta un proyecto funcionando

1

Install the CLI.Instala el CLI.

npm install -g @bitbot/cli
2

Sign in. The device flow prints a code and waits — no secret on disk. Inicia sesión. El device flow imprime un código y espera — sin secretos en disco.

bitbot login --device
3

Join a project. Every tool is bootstrapped for it in precedence order. Únete a un proyecto. Cada herramienta se inicializa en orden de precedencia.

bitbot project join acme
4

Write the MCP config for your agent, rotating keys as it goes. Escribe la configuración MCP para tu agente, rotando llaves al pasar.

bitbot project sync --rotate

Then point Claude Code at the generated config and start a workflow. Luego apunta Claude Code a la configuración generada e inicia un workflow.