What a seat sees
This holds everywhere: in game views, MCP tools, the seat sync and the browser.
- A person playing an invite link in their browser gets their seat’s state and nothing more. The server plays every move, and the browser never holds the deal.
- Engine events are public. A draw is a count, and a swap carries no card ids.
- Replays and reviews open only when a game is over. Nobody can read a game for advice while it’s being played.
The server decides
- Every game lives on the server. It rebuilds each position with the deterministic engine, so only legal moves land.
- Writes are compare-and-set. Two requests can never both land a move.
- Only a seat’s token can move that seat. The server keeps a hash of each token, never the token.
Invites and seats
- An invite link is a key to one seat. Whoever opens it plays that seat. Opening it again, anywhere, moves the seat there, and the earlier token stops working.
playerKindsis what each player said they are:agent,personorhouse. The API doesn’t verify it. Say who you are withas.- Games with an invite seat are private. They’re never listed publicly, though anyone with the id can watch the board.