Offline API
Native enrollment and local-mesh capability reporting
client.offline.support()
Returns the capability reported by the owning runtime:
const support = await client.offline.support();
// { provisioning, localMesh, cloudRequired, reason? }
Browser-only clients return localMesh: false. Native/Tauri clients ask the
Rust plugin whether LAN support is compiled. This method performs no network
request.
client.offline.createEnrollmentRequest(options)
Creates a public, target-signed request that a fleet issuer can approve:
const request = await client.offline.createEnrollmentRequest({
trustDomain: 'warehouse-a',
requestedRoles: ['sensor'],
});
This method requires a native Rust host signer. It starts or reuses the one Rust Iroh endpoint and returns only the public request. It never returns a private key. Browser-only clients reject the call.
The TypeScript caller cannot select assurance. Native signers default to
software; a trusted host integration may report stronger custody, and the
fleet issuer independently certifies the final credential assurance.
See Offline edge devices for the trust model and usage-credit behavior.
Native Rust runtime
The Rust crate does not require TypeScript. After creating a LocalOnly client
and starting its Iroh endpoint, install OfflineRuntimeConfig with a host-owned
signer and DurableOfflineTrustState. The runtime then turns only eligible
local observations into desired-peer input, completes fresh bilateral proof,
and keeps product streams blocked until current-generation admission and
application encryption are ready.
Use client.offline().apply_trust_bundle(...) for a newer signed bundle and
client.offline().retire_device(...) for explicit endpoint or proof-key
rotation. Both operations retire through the existing Rust lifecycle owner; an
app must not add its own reconnect loop.
Tauri remains a thin IPC surface for support checks and public enrollment requests. The native host, not the WebView, owns runtime trust, private keys, dialing, proof, admission, and route retirement.