Kindling · open protocol · v0.1
The introduction is the product.
Kindling is an open protocol for finding people. Your profile lives wherever you already keep it. Curators gather profiles into Pools. Nobody enters a Pool without saying yes, and nobody in the middle makes money by keeping two people apart.
| Project | Kindling Protocol |
|---|---|
| Drawing | Two layers and one handshake |
| Revision | v0.1 |
| Status | Stable |
| License | Text CC BY 4.0 · Code Apache 2.0 |
Drag the drawing sideways to follow the line.
The path
- Ask. Mira, the curator, asks to add Noor’s page to the Pool.
- Request. The Pool sends Noor a handshake by structured email: name, charter, curator, intent, visibility, and one click either way.
- Yes. Noor says yes. A no is remembered, and no answer expires after 14 days.
- Listed. Her entry is added with its consent_proof. Only people who said yes can answer a query.
- Leave. Noor can withdraw from any message, and it is processed within 60 seconds.
Callouts
- §2.2 A page you already have, read through h-card first.
- §3.1 A Pool is a JSON manifest anyone can host.
- §4.5 The curator’s verification level is always shown.
- §5.1 No entry without the owner’s consent. Silent inclusion is forbidden.
- §5.2 A decline is remembered. The same curator can’t ask again.
- §5.3 A withdrawal is processed within 60 seconds.
- §6.1 Messages travel as structured email. Email is the floor.
The protocol in six lines
- urla profile is a page you already have ·
noor.notion.example→ h-card read, gaps inferred, provenance kept§2 - pool“Queer creatives in LA” · curator mira · email-verified · unlisted§3
- askhandshake → noor · charter, curator, intent, one click either way§5.2
- yesnoor accepted ·
consent_proofrecorded · listed§3.4 - query“who’s up for a hike this weekend?” → only people who said yes can answer§5.1
- leavewithdraw at any time · processed within 60 seconds · declines are remembered§5.3
No app. Any client can do this. No operator. Pools are JSON anyone can host.
Why this exists
They make money on the wait, not the meeting.
Dating and friendship were broken by the same business model. The operator in the middle of a matchmaking app is paid while you’re still looking. Friendship never even got an app, because there was no way to charge for it.
People have already started routing around this in public. Dating docs on Google. Friendship spreadsheets on Notion. Personal pages on Carrd that read like profiles. The behavior is everywhere. What’s missing is a way to search, scale, and connect across those self-hosted pages without rebuilding the trap. Kindling is the layer that lets the existing behavior work as infrastructure.
- The dating doc.
docs.google.com/…/date-meA page, a photo, what you’re looking for, an email at the bottom. Already a profile. Kindling reads it as one. - The friendship spreadsheet.
notion.site/friends-in-berlinSomeone keeps a list of people who’d like to meet people. Already a Pool. Kindling gives it a manifest and a consent rule. - The personal page.
you.carrd.coWhatever you publish, wherever you publish it. The protocol has no opinion about the host, only that you control the URL.
How it works
Two open standards, stacked. The UI is yours.
Layer 1 · Profile. A page you already have becomes a profile.
There is no required format. The parser reads what’s there. IndieWeb h-card markup is the baseline; where it’s missing, an AI parser may infer from prose and layout, and it must record which fields were marked up and which were inferred. Kindling stores no profile data. Photos are referenced by URL and never copied. Add a kindling-noindex directive and no compliant Pool or crawler may list you.
| Field | What it holds |
|---|---|
| display_name | as published |
| intent_tags | what you’re open to |
| location | city, region, remote, anywhere |
| contact_methods | email, handles, scheduling links |
| verification_level | always visible to whoever is asking |
| messaging_preferences | who may write to you, and how |
Layer 2 · Pool. A Pool is a manifest anyone can host.
A JSON document in a public Git repository or behind a small API, grouping profile URLs by context: a city, a scene, an interest, a relationship orientation, a community. It declares who curates it, what it’s for, who can see it, and how consent works. Profiles and Pools are loosely coupled by URL, so one profile can sit in many Pools and leave any of them.
| Field | What it holds |
|---|---|
| curator | verified identities; level shown |
| charter | what the Pool is for and isn’t |
| visibility | public · unlisted · invite-only |
| consent_model | universal-opt-in · vouching-required · curator-only-adds |
| entries[] | each with its consent_proof |
| status | active · dormant · archived |
The whole protocol, playable
Nobody enters a Pool without saying yes.
Four self-hosted profiles, one Pool, one curator. Submit a URL and watch the handshake do its job. Then ask the Pool a real question and notice who can answer.
Profiles live where their owners host them
Nothing here is copied. A Pool caches a parsed sidecar only after its owner says yes. You are Mira, the curator: choose whose page to submit to “Queer creatives in LA”.
noor.notion.example
A Notion page with h-cardNoorshe/her
Email verifiedIllustrator in Echo Park. Up for a hike most weekends, and always glad to meet people who make zines.
Not asked
reza.carrd.example
A Carrd page, no markupRezahe/him
Signed in with OAuthStarted two small design studios. Glad to mentor a first-time founder over coffee in Silver Lake.
Not asked
mira.example
A personal siteMirashe/they
Email verifiedKeeps the list of queer creatives in LA who would like to meet. Curates the Pool and answers removal requests.
Curator of this Pool
Mira asks. The owner decides.
docs.google.example/jun/date-me
A dating docJunthey/them
Email verifiedSound designer in Highland Park. Dating in LA, and always happy to find friends for live music.
Not asked
The handshake
The handshake is a structured email. The owner gets the Pool’s name, charter, curator, intent, visibility, and one-click accept or decline. A decline is remembered and the same curator can’t resubmit. Silence expires in 14 days. Here you answer as the owner.
No request yet. In step 1, have Mira ask someone. The request appears here, as that person would receive it.
The Pool manifest
Entries stay empty until someone accepts. Every entry carries the consent_proof that put it there (§3.4).
{
"schema_version": "0.1",
"id": "queer-creatives-la",
"name": "Queer creatives in LA",
"curator": [
{
"identity": "mira@mail.example",
"display_name": "Mira",
"verification_level": "email",
"primary": true
}
],
"intent_tags": ["friendship", "creative-collaboration", "hiking-buddies", "mentoring", "dating"],
"visibility": "unlisted",
"consent_model": "universal-opt-in",
"curator_contact": "mira@mail.example",
"charter": "Queer artists, writers, musicians and makers in and around Los Angeles who would like to meet each other: for a hike, a collaboration, some mentoring, a friendship or a date. Not for recruiting, selling or promotion.",
"geographic_scope": {
"city": "Los Angeles",
"region": "California",
"country": "United States"
},
"status": "active",
"created_at": "2026-09-01T17:00:00Z",
"updated_at": "2026-09-01T17:00:00Z",
"entries": []
}Ask the Pool a real question
Any client can ask. Only profiles that said yes to this Pool can answer.
This is a demonstration of the protocol, not a product. The same steps happen in any implementation, in any interface someone cares to build.
Rules that don’t bend
The character of the protocol is in its MUSTs.
Most of the specification is plumbing. These are the lines that decide what kind of thing Kindling is. Each one links to the section that binds it.
- §5.1Silent inclusion is forbidden. There is no exception.A profile is never added to a Pool without the owner’s explicit consent, whatever the Pool’s consent model.
- §5.2A decline is remembered.Say no once and the same curator may not submit you again without your permission. Silence expires the request in 14 days.
- §5.3Leaving takes sixty seconds.Withdraw from any Pool at any time through the messaging channel. Implementations must process it within a minute of receipt.
- §2.5Your photos are never copied.Referenced by URL only. Kindling and Pools store no photo bytes. Your images stay where you put them.
- §1.3Nothing is charged at the connection layer.The protocol defines no chargeable surface between two people who want to meet. That is a stated non-goal, not a pricing decision.
- §4.5Who you’re talking to is always shown.Every profile carries a visible verification level: email, OAuth, curator-vouched, or unverified. A conforming UI must render it every time.
- §5.5Auto-accept can never be silent.Off by default, at most five rules, a notification for every event, and revocable after the fact. Convenience never outranks consent.
- §7.2Say no to strangers if you want to.Per-profile rules: open to all, pool-mates only, vouched only, no cold messages. Implementations must honor them, and shared block lists sit underneath.
- §9A Pool outlives its curator.Ninety days of inactivity and the Pool goes dormant. Active members can elect a new curator by two-thirds. Failing that it archives, readable and revivable.
- §6.1Email is the floor.Messaging rides on structured email, so it inherits decades of spam filtering and needs no new network. Richer transports may come; email stays as the fallback through v1.
Why a protocol and not an app
If TranquilTech disappeared tomorrow, the Pools would keep working.
Publishing the protocol before building anything on it is a commitment made in public. Profiles would still be readable. Other implementations would still run. That property can’t be bolted on later; it has to be designed in from the first line. A closed matchmaking app asking to be trusted has no leverage. A specification anyone can audit, fork, and re-implement has a different standing in the conversation.
The license is split on purpose. Code is Apache 2.0, so anyone can fork, vendor, and embed it. The spec text is CC BY 4.0, so it can be reused in books, articles, derivative specifications, and academic work without a negotiation. No single company can own the standard. That includes us.
Now · v0.1
StableTranquilTech maintains.
Initial maintainer. Pays for the first year of registry hosting. Changes land through an RFC process modeled on Rust’s.
v0.2
DraftIndependent maintainers join.
Implementers and IndieWeb regulars are invited onto the maintainer roster. Cryptographic identity and cross-Pool portability are on the draft.
By v1.0
PlannedA Working Group governs.
One Mycelial seat, two elected seats for independent implementers, one IndieWeb seat, and a rotating advisory. TranquilTech becomes one voice among several.
Build on it
Clone, validate a Pool, run a query. Under ten minutes, or it’s a bug.
# validate a Pool manifestnpx kindling-validate https://example.com/pools/queer-creatives-la # parse a profile URL into structured JSONnpx kindling-parse https://noor.example.com # ask a Pool a question in plain languagenpx kindling-discover --pool https://example.com/pools/queer-creatives-la \--query "who is up for a hike this weekend?"
The repository ships the spec, the JSON schemas for profiles, Pools, handshakes and messages, a validator, a parser, a reference handshake server, a starter discovery agent, a block-list publisher, and the registry source. It ships no consumer app. That’s the point.
Three ways to help now
- Specification feedback.Read it. Open issues for ambiguities, gaps, and overreach. Implementers, identity-protocol veterans, and IndieWeb regulars especially.
- Reference implementations.Build a Kindling client in your stack. A list, a search view, a printed zine. Send the link and the registry lists it.
- Founding Pool curators.Run a Pool. Curate it well. Write down what worked. The first curators are deciding what curation is as a craft.
Four ways to conform
The conformance classes of §11, in short.
- Compliant Pool host §11.1Implements the manifest, the handshake, and continuity, and publishes a
.well-known/kindling-poolfile. - Compliant Pool UI §11.2Shows verification level beside every profile, honors all three spam layers, supports withdrawal, never includes silently.
- Compliant parser §11.3Prefers h-card, records what was inferred, respects noindex, stores no photo bytes.
- Compliant messaging client §11.4Validates every envelope, surfaces verification level, applies identity-based gating.
Where things stand
Published first. Built on second.
- Specification
- Stable v0.1 is published and stable. Changes before v0.2 land as opt-in additions or clearly marked deprecations. Section numbers won’t move until a major version.
- Running on it
- Nothing yet Nothing at TranquilTech, yet. The protocol shipped before any product depends on it, on purpose.
- First implementation
- Planned Planned inside Mycelial. Pools become how members of a community find each other within and across Groves. First quarter 2027.
- Next
- Draft v0.2 in draft: cryptographic identity, cross-Pool identity portability, and voluntary post-introduction gratitude, which the spec says cannot be turned into a paywall.
Contacts
Write to the maintainers.
- Protocol maintainers
- josh@intellibotique.comSpec questions, implementation partnerships, contributing.
- Code of conduct
- josh@intellibotique.comConduct concerns, incident reports, community standards.