The formatAvailable

IDOP: a file format for documents that do things.

An IDOP document combines content, interface, logic and data in one portable file. Any conforming reader can open it, check it, and run it safely — and what you enter is saved back into the file.

IDOP 1.0 at a glance

File extension
.idop
Media type
application/vnd.idop+zip
Container
ZIP, with a fixed structure and a stored mimetype first
Code
HTML, CSS, JavaScript, JSON — under code/ only
Network
None, unless declared in the manifest and allowed by the user
State
Saved in the file, under storage/, as revisions
Specification
IDOP 1.0 · text CC BY 4.0

§ 01What it is

A document that carries its own behaviour.

Most documents are a record of something that was computed, decided or designed elsewhere. An IDOP document can contain the thing itself: the model behind a forecast, the rules behind a form, the exercise behind a lesson.

Technically, an .idop file is a ZIP archive with a small, strict structure: a manifest that says what the document is and what it may ask for, its interface and logic as ordinary web code, passive resources such as images and data, and its saved state. Because the structure is specified, a reader can check every byte of a file before anything in it runs.

The format is published as an open specification, with JSON Schemas and stable error codes, so that IDOP documents do not depend on any single application — including ours.

§ 02Why it exists

Three things documents have never been able to do together.

Compute where they are read

A reader can change an input and see the consequence, instead of trusting a number someone else derived. The logic travels with the content it explains.

Remember what you did

Entries, progress and choices are saved inside the file. There is no server holding the only copy of your work, and no account needed to keep it.

Stay safe to open

Interactive content usually means trusting whoever made it. IDOP is designed so that opening a file does not grant it anything you did not see and approve.

§ 03What makes it different

From a record of the work to the work itself.

IDOP is not meant to replace every document format. It is meant for documents that are more useful when they can be operated.

Traditional documents compared with IDOP documents
AspectTraditional documentIDOP document
ContentPrimarily static text, tables and imagesContent plus an interface that responds
BehaviourFixed presentationProgrammable behaviour, defined by the document
LogicLives in an external toolTravels inside the file, next to the content it explains
InteractionReading, annotating, printingApplication-like interaction: inputs, views, workflows
DataExported, copied or re-keyedSaved in the file as revisions; exportable as data
SafetyMostly passive content; macros and scripts vary by formatValidated before execution; sandboxed; no network unless allowed

When IDOP is the wrong choice

  • Text that only needs to be read and printed faithfully — a static format does that better.
  • Large applications with servers, accounts and many users editing at once.
  • Anything that must run without a conforming reader available.

§ 04What a document contains

Seven names, each with one job.

Every entry in an IDOP package begins with one of these roots. Anything else is refused. Select an entry to see what it holds and who writes it.

budget.idop

mimetypeIdentification

Spec §4.2

The first entry of every package, stored uncompressed. Its content puts the media type at byte offset 38, so software can recognise an IDOP file without unpacking it.

Executable
No
Written by
Producer
application/vnd.idop+zip

idop.jsonManifest

Spec §7

What the document is and what it may ask for: the application, the document’s identity and revision lineage, the entry point, and every network capability with the origins, methods and purpose it declares. It never contains a secret.

Executable
No
Written by
Producer; the reader updates the revision on Save
{
  "format": "https://idoplabs.com/ns/idop/package",
  "formatVersion": "1.0",
  "entryPoint": "code/index.html",
  "application": { "id": "com.example.budget",
                   "title": "Project budget" },
  "requiredCapabilities": []
}

code/Interface and logic

Spec §8

HTML, CSS, JavaScript and JSON — the only part of a package that can run. It runs inside the reader’s sandbox, with no network and no access to the reader. Inline scripts, remote URLs and dynamic evaluation are refused before anything runs.

Executable
Yes — in the sandbox only
Written by
Producer
code/
├── index.html   <script type="module" src="app.js">
├── app.js       await idop.storage.write(…)
└── style.css

resources/Passive files

Spec §4.3

Images, fonts and data files the interface displays. The reader serves them to the document by path; nothing under resources/ is ever executed, and a script placed there causes the package to be refused.

Executable
No
Written by
Producer
resources/
├── icon.svg
├── fonts/inter.woff2
└── data/rates.csv

storage/Saved state

Spec §10

The document’s data, saved in the file. The document reads and writes it only through the Runtime API; changes stay in a working copy until the user saves, and every Save produces a new revision.

Executable
No
Written by
The reader, on Save
// inside the document
const { text } = await idop.storage.read('model.json');
await idop.storage.write('model.json', next);

_idop/Reserved by the specification

Spec §4.3

Names the specification keeps for itself. IDOP 1.1 defines an optional thumbnail here; publisher signatures and encryption metadata are reserved for future versions. A 1.0 reader ignores this root.

Executable
No
Written by
Defined by later versions
_idop/
├── thumbnail.png    1.1 draft
├── signatures/      reserved
└── encryption/      reserved

extensions/Extension data

Spec §4.3

Data for named extensions, each under its own reverse-domain namespace, so extensions cannot collide with each other or with the format.

Executable
No
Written by
Producers of an extension
extensions/
└── com.example.review/
    └── comments.json

The complete rules — paths, limits, the manifest’s members — are in sections 4 to 8 of the specification. A walkthrough for developers is on the file format page.

§ 05How people use it

Received, opened, used, saved, sent on.

An IDOP document behaves like a file because it is one. This is the whole life of a document, as a person experiences it.

  1. 01

    Receive

    A colleague sends budget.idop, or you download it, or you start from a template.

  2. 02

    Open

    A reader validates the entire file. A broken or non-conforming file is refused, not half-run.

  3. 03

    Consent

    If the document declares network access, you see where it wants to go and why — and decide.

  4. 04

    Use

    The document runs in its sandbox. You work in it; it keeps your changes in a working copy.

  5. 05

    Save

    Saving writes a new revision into the same file. Nothing changes until you save.

  6. 06

    Share

    Send the file on, or share a link from IDOP Cloud. Your data travels in it; your keys do not.

§ 06Format, readers and IDOP Cloud

The format is the product. The reader is one way to use it.

IDOPThe file format and its specification: what a document is, and what any reader must do.
ReaderSoftware that opens, validates and runs IDOP documents. Anyone can build one from the specification.
IDOP CloudOur web platform: a reader, plus storage, sharing and templates, at cloud.idoplabs.com.

§ 07Architecture

How a reader runs a document.

Validation first, then a sandbox with a single, narrow channel to the reader. Every request the document makes passes through rules it cannot change.

Input

.idop file

Untrusted until proven otherwise.

Step 1 · Reader

Validation before execution

  1. Size limits
  2. ZIP structure, parsed independently
  3. mimetype
  4. Every path
  5. Bounded decompression, CRC
  6. Manifest
  7. Executable boundary
  8. Capabilities and consent

Any failure refuses the whole file, with a stable error code. Nothing runs before all checks pass.

Step 2 · Running

Sandbox

The document’s code. Opaque origin, no network, no access to the reader or other documents.

code/**

Reader

Answers each request — or refuses it.

  • Storage — a working copy of storage/
  • Network — only declared origins, after consent
  • Credentials — injected by the reader, never shown to code

Step 3 · Save

A new revision

Only storage/ and the revision in idop.json change. The result is validated again before it replaces the file.

The processing model of an IDOP reader, simplified. The normative text is in the specification, sections 9 to 12.

§ 08Use cases

Where IDOP is useful.

Documents whose value is in being used: explored, filled in, recalculated, kept.

annual-report.idop

BusinessDemonstration

Interactive report

A report where every figure can be opened to the numbers behind it, and every scenario can be tried.

renal-dosing.idop

HealthcareDemonstration

Clinical calculator

A scoring or dosing formula that carries its own references and versioned logic, so the calculation a reviewer approved is the one that runs. Illustration only — not medical software.

fractions-unit-3.idop

EducationTemplate available

Interactive course

Lessons, exercises and quizzes in one file a student keeps: progress is saved inside it, and it works offline.

survey-explorer.idop

DataDemonstration

Data exploration tool

A dataset with its own filters and views, so the reader explores the data rather than a screenshot of it.

§ 09Questions

Common questions about the format.

Is IDOP just a web page in a ZIP file?

The code is ordinary web code, which is deliberate: it is what most people who build interfaces already know. What IDOP adds is the contract around it — a fixed structure a reader can validate, a sandbox with no network by default, a small Runtime API for saving state, declared capabilities with user consent, and revisions saved into the file.

Do I need IDOP Cloud to open an .idop file?

No. Any reader that implements the specification can open IDOP documents. IDOP Cloud is the reader we build and operate; it also adds storage, sharing and templates.

Can a document access the internet?

Only if its manifest declares the exact origins, methods and purpose, and you allow it. Without that, a document has no network access at all. API keys are added by the reader and are never visible to the document.

What happens to my data?

A document saves its state inside the file, under storage/, when you choose to save. Each save creates a new revision. You can keep, copy, send or delete the file like any other.

Is the format stable?

IDOP 1.0 is a Candidate Recommendation: the container and manifest are frozen, with editorial changes only. Minor versions are additive — a 1.0 document stays valid. IDOP 1.1 is a working draft.

Read the specification, or open a document.

IDOP Cloud runs in the browser. Start from a template, open a file you were sent, or keep your own — no installation, and no account needed just to open a document.