Packages and templates share assemble, scheduler, then press. Bearer POST /v1/render or OAuth on /mcp. The press only compiles typst-package.
typst-package is files you send. typst-template is a web kind: a ref plus JSON, then the same scheduler and press. There is no press kind named template.
Forms, keys, and MCP on pdf.railman.io. Assembles templates. Never compiles.
Queue, cache, retries, DLQ. Only R2 writer. Only wallet debit.
Typst WASM. No public URL, no D1. Service binding is the capability.
Binds pdf-press-typst directly and is unbilled.
Who writes data.json, and whose wallet pays.
Caller sends the directory.
Caller wallet
web writes data.json from a ref plus JSON.
Caller wallet
Binds pdf-press-typst directly. Skips web.
Unbilled
Physical names stay frozen. Do not invent synonyms.
Session, API keys, MCP, and template assemble. Host pdf.railman.io.
Queue, content-addressed cache, retries, DLQ. The only wallet debit. Public callers cannot force a cache miss.
Physical name pdf-press-typst. Typst WASM, no public hostname, no D1.
One Durable Object per userId. 8000 credits a month. web never subtracts.
Isolated outbound HTTPS GET for CIMD. Physical name pdf-egress.
OAuth at /mcp. Same package and template shapes as HTTP. Third client path, not a third press.
HTTP, templates, and agents. Specs live on the tabs above.