> ## Documentation Index
> Fetch the complete documentation index at: https://www.offlineprotocol.com/docs/llms.txt
> Use this file to discover all available pages before exploring further.

> ## Agent Instructions
> These docs target Mesh SDK v0.27.0. Match the installed package and binding before generating code. Start at /getting-started/agents for task-specific reading paths.
> Call the company and product Offline Protocol, never Offline alone. Current packages: @offline-protocol/mesh-sdk 0.27.0 (React Native), @offline-protocol/id-react 0.2.0, @offline-protocol/id-react-native 0.3.3, @offline-protocol/pol 0.1.2 and @offline-protocol/cli 0.2.6. Canonical docs URLs start with https://www.offlineprotocol.com/docs.
> The Mesh SDK runs in a native app or gateway. A browser OfflineID SDK integration does not provide browser mesh transport. Local mesh operation does not require a portal account or API key. The Mesh SDK appId is a mesh app identifier the developer chooses, not the portal App ID (app_...) that OfflineID and Proof of Location require.
> Service RPC is signed plaintext in v0.27.0. Message delivery, durable local acceptance and backend commit are distinct outcomes. Use the workflow guide for the required application logic.
> Offline Protocol CLI 0.2.6 is on npm (@offline-protocol/cli, command offline). Its local MCP server, named offline-protocol, runs with npx -y @offline-protocol/cli@0.2.6 mcp serve and requires no login or key. Hosted MCP is at https://mcp.offlineprotocol.com/mcp with an app API key in Authorization: Bearer and the matching App ID in x-app-id; organization keys are rejected, and Claude Desktop, Claude.ai and ChatGPT cannot use it. Follow /tools/overview for setup and do not invent commands beyond it. MCP provides integration context and planning, not mesh execution; file-writing tools are local only.
> Phone Wi-Fi Direct and MultipeerConnectivity carry no data in v0.27.0. Use BLE or a provisioned relay. The receiver core ACKs before application persistence; use application acceptance for durable workflows.
> Proof of Location is Sepolia testnet witness evidence, not zero-knowledge proof or proof of presence. The geohash is public onchain. Read /proof-of-location/security before integration.

# Set profile image privacy

> Sets who can see a profile's image to EVERYONE, CONNECTIONS or NOBODY and returns the saved setting. Requires the signed-in user's JWT and X-App-Id.



## OpenAPI

````yaml patch /profiles/{username}/pfp-privacy
openapi: 3.1.0
info:
  title: Offline Protocol hosted API
  version: 1.0.0
  description: >-
    Hosted OfflineID authentication, profiles and connections. Send a user JWT
    and X-App-Id; a portal API key is not a user token. Endpoint-specific
    availability and response envelopes are documented below.
servers:
  - url: https://api.offlineprotocol.com/api/v1
security: []
paths:
  /profiles/{username}/pfp-privacy:
    patch:
      summary: Set profile image privacy
      description: >-
        Sets who can see a profile's image to EVERYONE, CONNECTIONS or NOBODY
        and returns the saved setting. Requires the signed-in user's JWT and
        X-App-Id.
      parameters:
        - name: X-App-Id
          in: header
          required: true
          schema:
            type: string
        - name: username
          in: path
          required: true
          schema:
            type: string
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              properties:
                pfpPrivacy:
                  type: string
                  enum:
                    - EVERYONE
                    - CONNECTIONS
                    - NOBODY
              required:
                - pfpPrivacy
      responses:
        '200':
          description: Success
          content:
            application/json:
              schema:
                type: object
                properties:
                  message:
                    type: string
                  data:
                    type: object
                    properties:
                      pfpPrivacy:
                        type: string
                        enum:
                          - EVERYONE
                          - CONNECTIONS
                          - NOBODY
                    required:
                      - pfpPrivacy
                required:
                  - message
                  - data
        '400':
          description: Invalid request
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '401':
          description: Authentication required
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '403':
          description: Not permitted
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '502':
          description: Gateway or upstream failure
          content:
            application/json:
              schema:
                anyOf:
                  - $ref: '#/components/schemas/Error'
                  - $ref: '#/components/schemas/GatewayError'
        '503':
          description: Service unavailable
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
      security:
        - bearerAuth: []
components:
  schemas:
    Error:
      type: object
      properties:
        message:
          type: string
        data:
          type:
            - object
            - 'null'
        error:
          type: object
          properties:
            message:
              type: string
            code:
              type: string
            retryAfter:
              type: integer
            currentHourCount:
              type: integer
            limit:
              type: integer
      required:
        - message
    GatewayError:
      type: object
      properties:
        message:
          type: string
        error:
          type: string
        upstream:
          type: string
        code:
          type:
            - string
            - 'null'
        detail:
          type: string
      required:
        - message
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      bearerFormat: JWT

````