What custody carries
Custody v1 carries only sealed document replication frames: deltas, snapshots, version offers and blob-removal reports from the DataStore. Direct messages, media chunks and requests for a snapshot or a blob are never deposited.- The depositor asks. When a device offers its own replication frame to neighbours because the recipient is out of reach, it adds a one-hop custody request. It can do this only while it retains the plaintext, so a frame offered after a restart carries no request.
- Forwarders strip the request. Every device removes the request from a third-party frame it transmits, so a deposit is always one hop, from the frame’s own sender over the link that proved it.
- The custodian holds what it could not forward. A frame with a request is forwarded normally first. Custody starts only when that forward would be abandoned.
- The custodian redelivers. When the recipient appears, the held frame goes straight to it, at most once per neighbour per hold. Meanwhile it can be re-originated toward other neighbours.
- A receipt settles nothing. The custodian may send the depositor a signed receipt. Only the recipient’s acknowledgement settles a message, so the depositor keeps its own outbox entry and retries unchanged.
Enable it
Custody is applied when the protocol is constructed; there is no runtime update. In React Native:CustodyConfig as ProtocolConfig(custody=...):
Omit a field to keep the core default. Python and Rust use the same fields in snake case. The core validates the bounds at construction and rejects, for example, a hold that is not shorter than the outbox lifetime.
Inspect and erase
getCustodyStats() returns what this device is holding and what it has done as a custodian and as a depositor. held and heldBytes are gauges; the rest are cumulative since start or the last erase, with one counter per refusal reason, so “custody is off” can be told from “nobody asked”. eraseCustody() drops every held frame and resets the counters. The DataStore wipeAll() erases custody as well. In Python the methods are get_custody_stats() and erase_custody() on pm.protocol.
See the networking API reference for the exact signatures.

