Skip to main content
Two facts decide how you query a world: which entities and fields it has, and how each field is stored. A world built from captured vendor data keeps identifying fields hashed, and secrets dropped, per its [redact] policy. describeWorld reports that per field, and storedForms turns a plaintext you know into the value the store actually holds.

Describe

describeWorld(slug, options?) reads the world’s head version through GET /api/public/worlds/{slug} and returns a WorldDescription. Pass the slug alone. The fields that matter for querying: The same document is what gateway worlds describe <slug> prints, and what it prints for a local world directory through the runtime. See the CLI page.

Look up a hashed field by its plaintext

storedForms(world, field, plaintext) returns every value the store may hold for that field given that plaintext: The rule is the one the runtime hashed with, byte for byte, so a stored form you compute here matches a row the world captured from the vendor. No lowercasing, no trimming: the plaintext is hashed exactly as given.
The salt is the connector’s slug, from connector.toml, not the world’s platform slug. They can differ: the spycloud-world world hashes under spycloud. storedForms reads the salt from world.redact.slug, which describeWorld supplies, so pass the description through unchanged. Building the policy by hand and salting with the platform slug produces digests that never match a row.
redactionOf(world.redact, field) returns which policy a field falls under, ranked the way the runtime applies them. Keep real data out covers the author’s side: how hash, drop, preserve and round are declared in connector.toml, which fields each one matches, and how to redact rows on the way in.

Which fields answer a plaintext query

A field marked hash or preserve answers a plaintext lookup, through storedForms. A field in the clear answers the plaintext as given. A field marked drop answers nothing, by policy: it was never written. Plan your queries from describeWorld first, and never import plaintext into a field the policy hashes. You rarely call storedForms yourself. queryRows(slug, entity, { where, resolve: true }) does the resolution for every value in where and runs the query, and its resolved field reports the form each value became, so a miss on a dropped field is explainable:

Where to go next