StillMade AIDeveloper docs
Browse documentation · SDK 0.1.0

Desktop capabilities

Request screen recording, cursor tracking, devices and other desktop capabilities with scoped consent.

Desktop capabilities for Blocks

The desktop host implements these capabilities on demand. Importing a Block, installing StillMade, or opening a preview does not request device permissions. The first operation displays StillMade's native consent dialog identifying the Block ID and version. An OS prompt may follow. Grants last for the mounted Block workspace, up to one hour; closing/reloading it or revoking access ends that grant. Imported UI receives neither native IPC nor grant tokens.

Declare the exact required scopes in manifest.permissions.desktop. Other permission families remain unchanged. Pure recipe/JavaScript execution stays sandboxed; the Block UI bridge requests desktop operations through the trusted host.

ScopeUI operationBehavior
screen.capturerecord.start, {kind:"screen"}Choose a screen or window, then record it.
cursor.trackcursor.track, or {cursor:true} on record.startGlobal cursor coordinates and display geometry; recordings sample at 10 Hz. Does not monitor clicks or keyboard input.
camera.capturerecord.start, {kind:"camera"}Camera recording after device/OS approval.
microphone.capturerecord.start, {kind:"microphone"}Microphone recording after device/OS approval.
clipboard.readclipboard.readReturns {text}; bounded to 100,000 characters.
clipboard.writeclipboard.write, {text}Explicit permission to replace clipboard text.
media.pickmedia.pickNative picker returns {assets} for up to 20 selected media files; no arbitrary path access.
notifications.shownotifications.show, {body}StillMade/Block-branded desktop notification; maximum one every ten seconds.
power.keep-awakepower.keep-awake, {enabled:true}Prevent app suspension until disabled, revoked, closed, or expired.
native.toolstool.status and declared tool.* operationsUse one exact versioned adapter for an approved installed desktop application.

The host always checks declarations. Declaring a scope does not grant it. A browser receives a clear desktop-required error; there is no silent paid/cloud fallback.

Approved native desktop tools

Native applications use a separate allowlisted adapter contract. The Block stays an ordinary sandboxed SDK package and must declare both permissions.desktop:["native.tools"] and a desktop-only platform matrix. manifest.desktopTools pins the exact adapter version and actions. A Block cannot supply an executable, command, path, environment variable, installer, or additional argument.

Natron adapter version 1 currently exposes launch, project.import, project.open, and project.render. Project import copies one user-selected .ntp file into that Block version's workspace and returns an opaque project ID. Open accepts only that opaque ID or latest. Render accepts a locally authorized StillMade video, bounded Reader/Writer node names, and a frame range of at most 10,001 frames. The trusted host invokes NatronRenderer with only the pinned project, -i, -w, host-resolved input/output paths, and the bounded range. It never accepts Natron's Python/interpreter flags or a Block-supplied path. The completed render is imported into the StillMade media library and returned as a typed video asset.

json
{
  "platforms":{"phone":{"supported":false,"reason":"Requires Natron and StillMade Desktop."},"browser":{"supported":false,"reason":"Requires Natron and StillMade Desktop."},"desktop":{"supported":true}},
  "permissions":{"project":[],"network":[],"filesystem":[],"secrets":[],"desktop":["native.tools","media.pick"]},
  "desktopTools":[{"id":"org.natron.Natron","adapterVersion":1,"actions":["launch","project.import","project.open","project.render"]}]
}

The mapped Natron Block uses video as both its primary typed input and output, with semantic video. This allows an explicit Project Type chain such as video producer → Natron → review/export Block. Its custom interface submits the connected original input and render settings to StillMade.run; the approved desktop executor invokes the renderer and returns the newly registered artifact with a bound native receipt. Source fixtures and JavaScript passthrough do not prove native execution. See Native desktop execution for src/desktop.json, offline admission, host callbacks and retained-result requirements.

Ready-to-import recording Blocks

Download the complete Screen recorder, Camera recorder, or Microphone recorder. These packages also ship in the SDK archive. Import one through StillMade’s normal review flow, then use its preview in the desktop app. Each includes a themed interface and pure runtime fixtures that preserve the media reference. The fixtures use synthetic references; they do not exercise your device.

The interface saves recording media before sending it through the runtime. If that handoff fails, Retry uses the saved recording without recording again.

Recording example

Manifest fragment:

json
{"permissions":{"project":[],"network":[],"filesystem":[],"secrets":[],"desktop":["screen.capture","cursor.track"]}}

Inside your validated view.javascript, attach explicit start/stop controls:

js
const start = document.getElementById('start');
const stop = document.getElementById('stop');
const status = document.getElementById('status');
start.addEventListener('click', async () => {
  try {
    await StillMade.desktop('record.start', {kind:'screen', cursor:true});
    status.textContent = 'Recording. Press Stop when finished.';
  } catch (error) { status.textContent = error.message; }
});
stop.addEventListener('click', async () => {
  try {
    const result = await StillMade.desktop('record.stop');
    // Declare matching video and metadata inputs in the Block manifest.
    // Your sandboxed runtime can pass these through as typed outputs.
    await StillMade.run({video:result.asset, cursor:{samples:result.cursor, displays:result.displays}});
    status.textContent = 'Recording saved to your local media library.';
  } catch (error) { status.textContent = error.message; }
});

record.stop returns {asset,cursor,displays,coordinates}. asset is a canonical media reference with assetId, versionId, kind, mime, and a device-local sm-media: URL. Cursor samples contain {x,y,time}: global device-independent screen coordinates and milliseconds relative to recording start. Multiple monitors can have negative coordinates. These are not automatically converted into cropped-window video coordinates. Share/upload media through the existing host media flow before teammates on other devices can use it.

record.cancel discards an active capture. session.close revokes all access and cancels capture. StillMade also renders a host-owned cancel/revoke control outside the Block iframe. Screen source selection happens for every recording. No preview can bypass consent or access the native bridge directly.

Current limits: one recording per Block workspace, 30 minutes, 128 MiB, WebM output. Hitting a limit cancels the recording; callers should stop and save earlier. Camera recording is video-only; microphone recording is audio-only. Optional {systemAudio:true} is implemented through Windows loopback; other platforms reject it explicitly. Microphone mixing, global click/keyboard hooks, remote-control automation, arbitrary subprocesses, and folder watching are not provided by these scopes.

Testing and installation

Test the pure typed-input/output runtime with synthetic media references and the regular SDK fixture tests. Then test the actual desktop operation interactively: allow, deny, stop, cancel, close, expired access, missing devices, source selection, and OS revocation. Passing a synthetic fixture or an Electron renderer test does not verify real OS permissions.

No extra native dependency, installer prompt, or blanket OS permission is introduced. macOS may require the user to enable StillMade in Screen Recording settings and restart it; StillMade cannot bypass that OS decision. Windows privacy settings may also block camera/microphone access. The grant dialog appears only when the Block requests the relevant operation.