FAQ
Artifact Publisher is Currico’s hosted, share-first product for the finished HTML work an agent produces. Sharing is the job: publish a self-contained document, hand over a stable unlisted link, and add review only when the deliverable needs it. These answers separate the supported core from the limits that still matter.
Product
Section titled “Product”What is Artifact Publisher?
Section titled “What is Artifact Publisher?”It turns a self-contained HTML deliverable into a stable unlisted link a recipient can open in a browser. It is for handing off reports, proposals, dashboards, microsites, and lightweight apps without sharing access to the agent, its chat history, the publisher’s machine, or the repository.
What can I publish?
Section titled “What can I publish?”One self-contained HTML document per artifact, up to 10 MiB of UTF-8. Include the markup, styling, and resources the document needs to render. Artifact Publisher is not a general web host, an application runtime, or an asset pipeline.
What is the supported core?
Section titled “What is the supported core?”Hosted delivery, stable unlisted links, immutable version history, revocation, optional page-level comments, feedback retrieval and replies, authenticated publishing through MCP with a scoped bearer key, and the two-origin isolation model.
Who is it for?
Section titled “Who is it for?”Agencies, consultants, operators, founders, and agent builders who need to hand client- or stakeholder-facing work to another person without inviting them into the tools that produced it.
Does it only work with one kind of agent?
Section titled “Does it only work with one kind of agent?”No agent brand is the product boundary. Artifact Publisher is MCP-first, so an agent or client with compatible MCP support can call the lifecycle tools. No compatibility matrix, managed connector catalogue, or integration beyond the MCP-compatible interface is claimed. See the MCP integration guide.
Sharing and recipients
Section titled “Sharing and recipients”Does a recipient need an account or an agent client?
Section titled “Does a recipient need an account or an agent client?”No. They open the unlisted link in a browser. There is no viewer account, install, repository invite, or access to the publisher’s agent or runtime.
What can a recipient see?
Section titled “What can a recipient see?”The published artifact and, when comments are enabled, its page-level comment interface. The link does not grant access to the agent runtime, chat history, source repository, or publisher’s machine. The publisher remains responsible for whatever the artifact itself contains — including any secret accidentally inlined into it.
What does “unlisted” mean?
Section titled “What does “unlisted” mean?”The link is not indexed and not listed on any public surface. It is a possession link, not authenticated access control.
Can an artifact load external images, fonts, APIs, or other assets?
Section titled “Can an artifact load external images, fonts, APIs, or other assets?”Not as a supported artifact. The artifact sandbox blocks network access, so external subresources and network-dependent behaviour will not work. Inline everything the recipient needs to see.
Can checkboxes or other UI sync live across viewers?
Section titled “Can checkboxes or other UI sync live across viewers?”Yes, when the artifact is opened on its review link. Artifact Publisher injects ArtifactRelayState (general JSON key/value sync; the helper names keep the product’s original codename, Artifact Relay) so every authorized viewer shares one small document without giving the sandboxed page network access. Checklist UIs may still use the older ArtifactRelayBoard helper; it reads and writes the same document. Sync does not run if someone opens only the raw artifact URL. Publishers can read or reset state through MCP (get_artifact_state, set_artifact_state, reset_artifact_state).
Feedback and versions
Section titled “Feedback and versions”Does every shared artifact need feedback?
Section titled “Does every shared artifact need feedback?”No. Sharing is the primary workflow, and page-level feedback is optional. A link can simply deliver a finished artifact. Comments are a workspace ceiling and a per-link setting, so they can stay off entirely.
How do comments work?
Section titled “How do comments work?”Comments are page-level and record the artifact version the recipient was viewing. They are not DOM- or line-anchored: there is no paragraph selection, region pin, or element marker. Reviewers are anonymous holders of the link and never authenticate.
How does an agent use feedback?
Section titled “How does an agent use feedback?”It calls get_feedback to retrieve structured comments with their versions, and reply_to_feedback to respond in the
associated thread. Retrieval is an explicit agent action — it is pull-based, and no webhook or push notification
capability is claimed.
Does the link change after an update?
Section titled “Does the link change after an update?”No. update_artifact appends a new immutable version while the stable link resolves to the current one. Earlier
versions are not edited in place, so a comment left on version 2 still describes version 2.
What does revocation do?
Section titled “What does revocation do?”revoke_artifact stops the artifact from being served, so a copied link stops resolving to content going forward. It
is enforced at the serving layer rather than by hiding a link in an interface. It cannot recall a document someone
already viewed, downloaded, or captured.
Security boundary
Section titled “Security boundary”Why are the reviewer surface and the artifact on separate origins?
Section titled “Why are the reviewer surface and the artifact on separate origins?”Artifact HTML is untrusted generated input. The hosted control and review surface runs on a different browser origin from the artifact, so the same-origin policy — not an editorial review step — prevents artifact script from reading the control origin’s DOM or storage. The artifact is embedded in a sandboxed iframe, and no cookie is ever set on the artifact origin, so there is no artifact-origin session for a document to reach for. Read the architecture and threat model.
Does that mean artifacts are safe?
Section titled “Does that mean artifacts are safe?”No absolute guarantee is claimed. Two origins, sandboxing, a restrictive control-surface CSP, and the absence of an artifact cookie are containment measures with stated residual risk — they depend on browser enforcement, and they do not inspect what an artifact says or shows inside its own frame. The publisher still decides what goes into a document, and each design should be evaluated against the sensitivity of its content.
How is publishing authenticated?
Section titled “How is publishing authenticated?”With a scoped bearer API key sent on the MCP connection. Each tool declares the scope it needs, and
workspace:configure is separate from publishing so a publish-only key cannot change workspace defaults. There is no
OAuth, SSO, team model, or identity-based client authorisation.
Can a client raise a platform limit?
Section titled “Can a client raise a platform limit?”No. The 10 MiB ceiling, rate limits, origin isolation, storage key layout, security headers, and visibility are platform guardrails. Naming one in a settings patch is rejected with the offending keys listed, rather than silently ignored — an agent should never believe it raised a limit it did not.
Is Artifact Publisher compliance certified or independently audited?
Section titled “Is Artifact Publisher compliance certified or independently audited?”No compliance certification, independent security audit, penetration test, or attestation is claimed. The architecture documentation describes the boundary and its residual risks without making those claims.
Limits and claims
Section titled “Limits and claims”- Self-contained HTML only, one document per artifact, up to 10 MiB of UTF-8
- Page-level comments only; no DOM- or line-anchored feedback
- Unlisted possession links, not per-recipient identity or an access audit trail
- External assets and network-dependent content are not supported
- Not a general web host, application runtime, or content-review service
- No compliance certification, audit, penetration test, or attestation is claimed
Artifact Publisher gives agents a hosted delivery path for finished HTML work. It does not claim to replace identity-based document access, a general hosting platform, or a compliance program.