Skip to main content

TeaQL Federal Protocol Boundary

TeaQL Federal Protocol (TFP) transports governed TeaQL queries and audited mutations between runtimes that share a domain model. It does not transport raw SQL and it does not let a client replace server-owned identity, tenant, permission, purpose policy, or execution limits.

Roles are asymmetric​

A runtime may implement a client, a server endpoint, or both. Existence of one role does not imply the other, and role conformance does not automatically prove a cross-language pair. The current per-language role and execution rows are in Cross-language Conformance Status.

Native APIs and portable transport​

Native generated Q APIs are broader than the portable TFP v1 subset. The portable profile includes governed predicates, projection, order, bounded offset/limit, and relation facets with explicit constraints. Operations shown as partial in the TFP column must not be serialized through an invented wire shape merely because every native runtime implements them.

Trusted endpoint boundary​

The endpoint maps every submitted entity, field, relation, operator, projection, order, aggregate, and writable mutation field through a trusted allowlist. It owns:

  • tenant, actor, roles, and authorization policy;
  • hard result, offset, depth, and shape limits;
  • purpose approval and audit enforcement;
  • optimistic-version checks and writable-field policy;
  • provider selection and context assembly.

Unknown, duplicate, malformed, or forbidden input fails closed. Provider error details and value-bearing diagnostic SQL are not returned to protocol clients.

Dynamic expressions​

Caller-supplied expression trees are a restricted, explicit opt-in deployment profile. Internet-facing endpoints keep them disabled unless the deployment owner has retained allowlist, resource-limit, tenancy, policy, and negative evidence. Generated language-native Q/E APIs are not reclassified as arbitrary dynamic expressions.

For application guidance, start with the TypeScript scenarios or another runtime whose role is shown in the current matrix. Do not infer an unsupported client or endpoint role from a generic HTTP library.