Skip to content

State Cards, Capture Sessions, and Capsules

State Cards, Capture Sessions, and Capsules

Section titled “State Cards, Capture Sessions, and Capsules”

ScenarioDeck separates the object you work with from the immutable technical material underneath it.

State Card
└─ Capture Session
├─ semantic action timeline
├─ meaningful checkpoints
├─ selected Saved state
├─ Recorded Journey, when available
└─ referenced State Capsule material

A State Card is the named Library item you select, inspect, reproduce, revise, compare, or share.

It presents the safe information needed to choose the next action, such as:

  • name, description/objective, and source context;
  • Saved state and Recorded Journey availability;
  • authentication and protected-value requirements;
  • checkpoints, actions, replayable exchanges, and console evidence;
  • sharing readiness;
  • latest-run evidence and relevant recovery states.

Technical IDs, digests, low-level provenance, and storage details remain secondary disclosures.

A Capture Session is the bounded versioned reproduction recording behind a State Card. It contains:

  • approved semantic user actions;
  • meaningful automatic and manual checkpoints;
  • a selected Saved state;
  • Recorded Journey coverage and manual barriers where applicable;
  • safe Capture context;
  • curation, compatibility, integrity, and provenance;
  • references to immutable browser/API replay material.

Saved state and Recorded Journey are two ways to reach the useful state from the same Reproduce launcher. ScenarioDeck stops rather than guessing when current code has drifted or a semantic action is missing, ambiguous, unsafe, or unsupported.

Older compatible Cards may contain less evidence or have no Recorded Journey. ScenarioDeck does not invent actions or a Journey that were never captured.

A State Capsule is immutable ordinary reproduction material referenced by the Capture Session.

Within supported scope it may contain route, safe browser/form state, selected redacted HTTP evidence, request occurrence identity, integrity metadata, and redaction/exclusion evidence.

Ordinary portable State Capsule material does not contain raw session cookies/tokens, Authorization headers, your browser profile, local Auth Binding values, or a database/server-memory/environment snapshot.

A supported sensitive value explicitly retained by the creator is not turned into ordinary portable State Capsule data.

Instead, ScenarioDeck keeps it behind the OS-protected machine-local boundary and stores only the safe relationship required by the local workflow. Using a retained value requires explicit authorization for the reproduction run, and ordinary sharing remains unavailable while the Card requires it.

If Review confirms Discard, ScenarioDeck leaves the original finalized Capture immutable, creates a sanitized derived Session, and replaces that protected automatic step with a manual Journey barrier. The saved Card can then use ordinary credential-free sharing when no other blocker remains.

The current Public Beta does not transfer protected values to another user.

Changes do not silently rewrite a source Capture Session or State Capsule.

For a supported replayable JSON response, Desktop can expose a bounded redacted projection in Form, Tree, or JSON mode. You review the exact safe diff, apply a validated overlay, and save the result as an immutable revision.

The editor does not grant general access to captured request data, headers, cookies, credentials, binary bodies, or arbitrary original payloads. Unsupported, stale, oversized, or unverifiable projections are not editable.

A State Card may declare a non-secret Auth Persona requirement. The machine-local Auth Binding that satisfies it remains outside ordinary portable State Card material.

A Development Profile login is also machine-local. If another device or a Clean Session needs authentication, ScenarioDeck uses the approved local recovery instead of silently transferring hidden login state.

One supported State Card can be packaged as a temporary encrypted ordinary share:

State Card
→ encrypted portable bundle
→ recipient imports locally
→ recipient chooses current local target and authentication
→ Reproduce

Ordinary sharing excludes machine-local protected values, browser-profile contents, local Auth Bindings, and local sign-in state. Share/receive/import is available in Free Capture; Developer access is required only when the recipient chooses to execute the reproduction against current code.

A one-card share is not a Team workspace. Shared organization libraries, members/seats, organization policies, audit/admin controls, and persistent Team storage remain separate future capabilities.