Skip to main content

Services and events

The service contract is a sequence of bounded guest invocations managed by the selected Glixo host. The host is designed to own activation, account grants, schedules, authenticated webhook ingress, leases, retries, health, graceful stop, and checkpoints. Mail Watch remains Preview pending live Graph acceptance; its fixture-backed installed-host journey has a narrower qualification. A guest does not need an unbounded loop to remain useful.

Email and event flow

The Mail Watch reference implements Microsoft Graph's per-folder message delta flow, stores opaque continuation state, and publishes a versioned event. The four language guest fixtures passed positive and malicious-cursor probes through the protocol-2 framed host. In addition, the TypeScript guest component from the signed package, artifact SHA-256 466438B454FDC396161CB519114FDEFA36B92820E9322F89DA6CA18D00F3673B, passed a persisted Code.Server scheduler journey on runner pin 9CBB7DA99521D65B88955653D2E2E55ACA41FC588D9F1A8B8F4E4A2F86627D30. The run exercised initialization, wake, replay, health, and stop with database-backed account grants, encrypted OAuth configuration, checkpoint persistence, outbox deduplication, and domain-event delivery; Graph HTTP used a deterministic fixture. This qualifies that installed-host fixture journey for the exact TypeScript artifact. It does not qualify C#, Go, or Rust installed-host journeys, or live Graph delivery: no real Graph credentials, mailbox, or network request were used. The first slice is Inbox metadata; fetching message bodies needs a separate grant. Consumers must be idempotent because external mail and event delivery cannot offer exactly-once processing.

The account configuration rejects undeclared fields, requires a protected oauth slot for delegated Microsoft Graph Mail.ReadBasic, and bounds maxPagesPerWake to an integer from 1 through 5 (default 5). Glixo injects the credential through an invocation-scoped lease; the guest does not read or store the token. The configuration schema and Mail Watch notes are linked from the immutable public source identity in Reference.

The durable event store owns event records, replay, and acknowledgements. SignalR wakes connected clients; clients then reconcile authoritative state. Workflow Creator consumes the same authorized event through an explicit workflow rule. A notification or event does not silently send content to an LLM or start agent work.

Placement and lifecycle

Service execution belongs to the selected server or cell. A mailbox listener should remain available on an authorized headless cell without an open panel. Mobile background behavior depends on the configured host and operating-system lifecycle. On a GUI desktop, service ownership follows the desktop-daemon policy.

Status is reported per provider, artifact, fixture, and host journey. The source snippets and remaining acceptance gaps appear in Tutorials. Live Graph account consent and delivery remain open, and the persisted fixture journey alone does not qualify a live mail integration.