GuideStart here3 min read
The Shell & Harness
The HarnessThe composition that runs the work: its selected resources, runtime context, and isolated environment.For exampleThe Harness connects your sketch to its drawing library and runs it inside the Cage.Full glossary entry → runs the work. The ShellThe opening program and interface around creator content. The canonical KEEL verification shell owns the protected checks and K controls.For exampleOpen the K control to inspect the files and checks behind the displayed work.Full glossary entry → opens around it and lets you inspect its files and checks.
Select an underlined word to see what it means.
In this guide
Your original image remains the artwork file. A reusable display Part opens it inside the Shell, where the viewer can inspect its checks.
The artwork comes with opening instructions.
Imagine receiving an animation together with the exact player it needs. The ShellThe opening program and interface around creator content. The canonical KEEL verification shell owns the protected checks and K controls.For exampleOpen the K control to inspect the files and checks behind the displayed work.Full glossary entry → serves that opening role in a browser. The HarnessThe composition that runs the work: its selected resources, runtime context, and isolated environment.For exampleThe Harness connects your sketch to its drawing library and runs it inside the Cage.Full glossary entry → is the larger composition: the work, its PartsReusable components included in a work, with their own identities and permissions.For exampleSeveral artworks can share the same verified drawing library.Full glossary entry →, and the environment in which it runs.
The standard KEEL shell is shared. Each work can reference the registered copy and its exact PartsReusable components included in a work, with their own identities and permissions.For exampleSeveral artworks can share the same verified drawing library.Full glossary entry → instead of paying to upload another complete player.
Check first, then open.
A MarkA file's computed fingerprint, also called a digest or hash. A reader recomputes it to check the bytes.For exampleChanging the sketch's background color changes its Mark. A filename alone would not reveal that change.Full glossary entry → is a fingerprint computed from a file. The CrucibleThe verification layer. Its browser checks compare recovered files with the fingerprints and sizes the work declared.For exampleA changed script fails its check before the default shell opens it.Full glossary entry → checks that the recovered files match the declared MarkA file's computed fingerprint, also called a digest or hash. A reader recomputes it to check the bytes.For exampleChanging the sketch's background color changes its Mark. A filename alone would not reveal that change.Full glossary entry → and sizes. The default ShellThe opening program and interface around creator content. The canonical KEEL verification shell owns the protected checks and K controls.For exampleOpen the K control to inspect the files and checks behind the displayed work.Full glossary entry → performs those checks before it opens the art.
Creator code runs inside the CageThe isolated browser box where creator code runs. The default environment does not give it a wallet or unrestricted network access.For exampleAn animated work can draw inside its box without receiving control of the gallery's wallet.Full glossary entry →, an isolated browser box. The verification controls remain outside that box, so the artwork cannot edit its own result.
Technical detail: authentic shell and resource checks
Resolve the committed canonical shell and exact graph. Verify stored lengths and digests, decode within declared limits, then verify decoded lengths and digests. Mount creator content in an opaque child iframe. The shell itself must be the authentic committed version; a substituted host-served verifier does not inherit its guarantee.
Choose a presentation deliberately.
The normal creator path uses the registered KEEL verification shell. Some integrations support a separately registered creator shell. Choosing direct access to a raw artifact means there is no shell interface around it.
A presentation-only shell describes its own behavior; it cannot claim the canonical shell’s verification. The underlying artifact remains identifiable whichever presentation is selected.
| Presentation | What it means |
|---|---|
| Default KEEL shell | Protected verification controls and the canonical resource checks |
| Compatible registered shell | An explicitly selected presentation with its own declared behavior |
| Raw artifact | Direct access to the committed media or code, with no shell interface |
A gallery decides what it can run.
A host is the site or application displaying the work. It controls which media, scripts, and network requests can run inside its page. Carrying a player with a work does not override those limits.
That is why the same SlabThe collectible token recorded in your wallet. It identifies an owned item and points to its work.For exampleYou collect Tidal Study #7. That token is your Slab; the artwork files have their own storage records.Full glossary entry → can have a working interactive view in one place and a static thumbnail in another.
The work can only use allowed capabilities.
KEEL calls the checked boundary around the CageThe isolated browser box where creator code runs. The default environment does not give it a wallet or unrestricted network access.For exampleAn animated work can draw inside its box without receiving control of the gallery's wallet.Full glossary entry → a SeamThe checked, limited interface across the Cage boundary.For exampleInformation crossing the Seam must match the allowed shape and size.Full glossary entry →. A request through it is a KnockA request made by the work through the Seam. The request itself grants no permission.For exampleA future host capability could handle a Knock only if that action is explicitly supported and allowed.Full glossary entry →. A GuardThe declared limits on what the work may do.For exampleA Guard can limit the runtime to the declared files and read-only context.Full glossary entry → describes allowed behavior, and the AccordThe permissions that all relevant parties allow together: artist, included parts, host, and chain. The most restrictive boundary still applies.For exampleA gallery that disallows network access does not acquire that permission because an artwork requests it.Full glossary entry → is the permission set allowed by all relevant parties.
The default ShellThe opening program and interface around creator content. The canonical KEEL verification shell owns the protected checks and K controls.For exampleOpen the K control to inspect the files and checks behind the displayed work.Full glossary entry → shares a limited set of read-only information. Artwork cannot use it to sign transactions or access a wallet.

