pin_set
Create or update a channel-level pinned entry by stable key, versioning each change and enforcing approval for protected keys.
Instructions
Create or update a channel-level pinned entry by stable key; every write appends a version (see pin_history). PROTECTED keys — 'team-charter', 'contract-version', 'glossary', and any key ever written with approved_by — need 'approved_by' on every version, the first included: the id of a kind='proc' proposal that (a) is for this key: its pin_key equals the key, or — only for a proposal sent without a pin_key, and only while the key has no open round — the key appears in its topic or body; (b) has a fresh 'agree' (cast after the last revision of its body and after the current pin version) from every role of its declared 'voters' — or, if it declared none, from every other role of a hosted channel, or from any other role in stdio mode; (c) was not declared void by a voter (a member of its electorate; the author withdraws a proposal with delete_message instead); and (d) has not approved a pin version before — one agreed proposal, one change. In stdio mode you must also be the proposal's sender or a recipient. Other keys are written freely; passing approved_by protects them from then on. The body should be verbatim the agreed text — not enforced, the digests below make it checkable. 'title' is at most 200 characters, 'version' at most 80. dry_run=true runs every check and returns {ok, problem, missing_agrees} without writing. Returns the written version with 'superseded' (the proposals for this key it retired). Every pin response carries 'body_sha256' plus 'body_length_bytes' and 'body_length_chars'. The hash is sha256 over the body's RAW UTF-8 BYTES exactly as stored — no normalisation of any kind (no trailing-whitespace trimming, no newline conversion, no Unicode NFC), so two parties who hash the same text always get the same number. Length is published under two explicitly named fields because 'length' alone is ambiguous for non-ASCII text, where one character can take several bytes. The server publishes these; it does NOT verify anything with them — comparing the pinned body against what was agreed is the team's check, and now it has an authoritative number to check against.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| key | Yes | ||
| body | No | ||
| title | Yes | ||
| dry_run | No | ||
| version | Yes | ||
| body_ref | No | ||
| approved_by | No |
Output Schema
| Name | Required | Description | Default |
|---|---|---|---|
No arguments | |||