Skip to content

FAQ

Artifact Publisher is Currico’s hosted, share-first product for the finished HTML work an agent produces. Sharing is the job: publish a self-contained document, hand over a stable unlisted link, and add review only when the deliverable needs it. These answers separate the supported core from the limits that still matter.

It turns a self-contained HTML deliverable into a stable unlisted link a recipient can open in a browser. It is for handing off reports, proposals, dashboards, microsites, and lightweight apps without sharing access to the agent, its chat history, the publisher’s machine, or the repository.

One self-contained HTML document per artifact, up to 10 MiB of UTF-8. Include the markup, styling, and resources the document needs to render. Artifact Publisher is not a general web host, an application runtime, or an asset pipeline.

Hosted delivery, stable unlisted links, immutable version history, revocation, optional page-level comments, feedback retrieval and replies, authenticated publishing through MCP with a scoped bearer key, and the two-origin isolation model.

Agencies, consultants, operators, founders, and agent builders who need to hand client- or stakeholder-facing work to another person without inviting them into the tools that produced it.

No agent brand is the product boundary. Artifact Publisher is MCP-first, so an agent or client with compatible MCP support can call the lifecycle tools. No compatibility matrix, managed connector catalogue, or integration beyond the MCP-compatible interface is claimed. See the MCP integration guide.

Does a recipient need an account or an agent client?

Section titled “Does a recipient need an account or an agent client?”

No. They open the unlisted link in a browser. There is no viewer account, install, repository invite, or access to the publisher’s agent or runtime.

The published artifact and, when comments are enabled, its page-level comment interface. The link does not grant access to the agent runtime, chat history, source repository, or publisher’s machine. The publisher remains responsible for whatever the artifact itself contains — including any secret accidentally inlined into it.

The link is not indexed and not listed on any public surface. It is a possession link, not authenticated access control.

Can an artifact load external images, fonts, APIs, or other assets?

Section titled “Can an artifact load external images, fonts, APIs, or other assets?”

Not as a supported artifact. The artifact sandbox blocks network access, so external subresources and network-dependent behaviour will not work. Inline everything the recipient needs to see.

Can checkboxes or other UI sync live across viewers?

Section titled “Can checkboxes or other UI sync live across viewers?”

Yes, when the artifact is opened on its review link. Artifact Publisher injects ArtifactRelayState (general JSON key/value sync; the helper names keep the product’s original codename, Artifact Relay) so every authorized viewer shares one small document without giving the sandboxed page network access. Checklist UIs may still use the older ArtifactRelayBoard helper; it reads and writes the same document. Sync does not run if someone opens only the raw artifact URL. Publishers can read or reset state through MCP (get_artifact_state, set_artifact_state, reset_artifact_state).

No. Sharing is the primary workflow, and page-level feedback is optional. A link can simply deliver a finished artifact. Comments are a workspace ceiling and a per-link setting, so they can stay off entirely.

Comments are page-level and record the artifact version the recipient was viewing. They are not DOM- or line-anchored: there is no paragraph selection, region pin, or element marker. Reviewers are anonymous holders of the link and never authenticate.

It calls get_feedback to retrieve structured comments with their versions, and reply_to_feedback to respond in the associated thread. Retrieval is an explicit agent action — it is pull-based, and no webhook or push notification capability is claimed.

No. update_artifact appends a new immutable version while the stable link resolves to the current one. Earlier versions are not edited in place, so a comment left on version 2 still describes version 2.

revoke_artifact stops the artifact from being served, so a copied link stops resolving to content going forward. It is enforced at the serving layer rather than by hiding a link in an interface. It cannot recall a document someone already viewed, downloaded, or captured.

Why are the reviewer surface and the artifact on separate origins?

Section titled “Why are the reviewer surface and the artifact on separate origins?”

Artifact HTML is untrusted generated input. The hosted control and review surface runs on a different browser origin from the artifact, so the same-origin policy — not an editorial review step — prevents artifact script from reading the control origin’s DOM or storage. The artifact is embedded in a sandboxed iframe, and no cookie is ever set on the artifact origin, so there is no artifact-origin session for a document to reach for. Read the architecture and threat model.

No absolute guarantee is claimed. Two origins, sandboxing, a restrictive control-surface CSP, and the absence of an artifact cookie are containment measures with stated residual risk — they depend on browser enforcement, and they do not inspect what an artifact says or shows inside its own frame. The publisher still decides what goes into a document, and each design should be evaluated against the sensitivity of its content.

With a scoped bearer API key sent on the MCP connection. Each tool declares the scope it needs, and workspace:configure is separate from publishing so a publish-only key cannot change workspace defaults. There is no OAuth, SSO, team model, or identity-based client authorisation.

No. The 10 MiB ceiling, rate limits, origin isolation, storage key layout, security headers, and visibility are platform guardrails. Naming one in a settings patch is rejected with the offending keys listed, rather than silently ignored — an agent should never believe it raised a limit it did not.

Is Artifact Publisher compliance certified or independently audited?

Section titled “Is Artifact Publisher compliance certified or independently audited?”

No compliance certification, independent security audit, penetration test, or attestation is claimed. The architecture documentation describes the boundary and its residual risks without making those claims.

  • Self-contained HTML only, one document per artifact, up to 10 MiB of UTF-8
  • Page-level comments only; no DOM- or line-anchored feedback
  • Unlisted possession links, not per-recipient identity or an access audit trail
  • External assets and network-dependent content are not supported
  • Not a general web host, application runtime, or content-review service
  • No compliance certification, audit, penetration test, or attestation is claimed

Artifact Publisher gives agents a hosted delivery path for finished HTML work. It does not claim to replace identity-based document access, a general hosting platform, or a compliance program.